Skip to content

chore(deps): bump cryptography from 47.0.0 to 50.0.0 in /envs/opencode_env - #1061

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/envs/opencode_env/cryptography-50.0.0
Closed

chore(deps): bump cryptography from 47.0.0 to 50.0.0 in /envs/opencode_env#1061
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/envs/opencode_env/cryptography-50.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 5, 2026

Copy link
Copy Markdown
Contributor

Bumps cryptography from 47.0.0 to 50.0.0.

Changelog

Sourced from cryptography's changelog.

50.0.0 - 2026-07-31


* **SECURITY ISSUE**:
  :func:`~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der`
  and its PEM and S/MIME variants no longer expose distinguishable errors or
  timing when unwrapping a ``RecipientInfo``'s ``encryptedKey``, which could
  act as a Bleichenbacher oracle for callers that decrypt untrusted messages.
  A random key is now substituted on failure, as described in :rfc:`3218`.
  Credit to **@X1AOxiang** for reporting the issue. **CVE-2026-69247**
* Deprecated Diffie-Hellman key exchange over finite fields (FFDH).
  Everything FFDH is deprecated, including the types in
  ``cryptography.hazmat.primitives.asymmetric.dh`` and loading FFDH keys or
  parameters with the key loading APIs. Users should migrate to a more
  modern key exchange algorithm.
* Added ``xof()`` class methods to
  :class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and
  :class:`~cryptography.hazmat.primitives.hashes.SHAKE256` for constructing
  algorithm instances configured for use with
  :class:`~cryptography.hazmat.primitives.hashes.XOFHash`.
* The :mod:`X.509 verification <cryptography.x509.verification>` APIs are now
  considered stable and are subject to our API stability policy.
* Added the :doc:`/cobblestone` recipe, an implementation of the
  Cobblestone-128 and Cobblestone-256 instantiations of the `C2SP
  chunked-encryption specification
  <https://c2sp.org/chunked-encryption>`_ for streaming authenticated
  encryption of large messages.
* Parsing a Signed Certificate Timestamp list now rejects encodings that
  carry trailing bytes after the list or after an individual SCT, instead of
  silently ignoring them.
* Added support for using :class:`~cryptography.x509.Name` as a field type in
  the :doc:`/hazmat/asn1/index` module.
* Loading a public key or an EC private key now rejects DER where the
  ``subjectPublicKey`` (or EC ``publicKey``) ``BIT STRING`` declares a non-zero
  number of unused bits, instead of silently ignoring it.
* Parsing a CRL entry's ``InvalidityDate`` extension now rejects a
  ``GeneralizedTime`` that carries fractional seconds or another non-DER form,
  matching the strict encoding already required for every other X.509 time
  field.
* :func:`~cryptography.x509.ocsp.load_der_ocsp_request` and
  :func:`~cryptography.x509.ocsp.load_der_ocsp_response` now reject a request
  or response whose ``version`` field is not ``v1``, the only version defined
  by RFC 6960, matching the version validation already performed when loading
  certificates, CSRs and CRLs.
* :class:`~cryptography.hazmat.primitives.hashes.XOFHash` is now supported
  when building against AWS-LC.
* HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when
  building against AWS-LC.
* Diffie-Hellman (:doc:`/hazmat/primitives/asymmetric/dh`) is now supported
  when building against AWS-LC.
</tr></table> 

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note

Medium Risk
Major bump of a security-critical transitive library may change crypto/X.509 behavior at runtime; impact is limited to lockfile resolution unless PKCS#7 or deprecated FFDH APIs are used directly.

Overview
Updates the envs/opencode_env lockfile so the transitive cryptography dependency moves from 47.0.0 to 50.0.0 (pulled in via authlib; not a direct pyproject.toml dependency).

This is a major release that includes a security fix for PKCS#7 encryptedKey decryption (CVE-2026-69247, Bleichenbacher-style oracle mitigation) plus stricter X.509/OCSP parsing and deprecation of finite-field Diffie-Hellman. No application source in this PR—only resolved package versions in uv.lock.

Reviewed by Cursor Bugbot for commit 6cb3cf5. Bugbot is set up for automated code reviews on this repo. Configure here.

Bumps [cryptography](https://github.com/pyca/cryptography) from 47.0.0 to 50.0.0.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@47.0.0...50.0.0)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 50.0.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added Dependencies python:uv Pull requests that update python:uv code labels Aug 5, 2026
@bot-ci-comment

bot-ci-comment Bot commented Aug 5, 2026

Copy link
Copy Markdown

The docs for this PR live here. All of your documentation changes will be reflected on that endpoint. The docs are available until 30 days after the last update.

@burtenshaw burtenshaw added environment size: small Small pull request labels Aug 5, 2026 — with Cursor

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Alignment Review Report

PR #1061chore(deps): bump cryptography 47.0.0 → 50.0.0 in /envs/opencode_env (dependabot[bot], native dependabot/uv/envs/opencode_env/cryptography-50.0.0). Scope: 1 file, envs/opencode_env/uv.lock (+191/−194). Lock-only transitive bump. Security-positive.

Automated Checks

  • Lint: PASS (for this PR). .claude/hooks/lint.sh exits 1 only on ~26 pre-existing envs/**/*.py reformat candidates (the long-standing opencode_env x8 + pi_env x5 from #999). This PR changes only uv.lock (TOML — not linted by the hook or CI; CI's lint job scopes to src/ tests/), so none of the flagged files are yours.
  • Debug code: CLEAN. check-debug.sh scans src/ only; every hit is pre-existing (containers/*, generic_client.py doc-examples, serve.py TODO). Nothing in this diff.

Open RFCs Context

Active RFCs on this branch: 000/001/002/003/004 (Rubrics)/005 (Agentic Harnesses, In Review)/010 (Token World Model, Draft). None govern packaging / dependency management / PyPI index selection. opencode_env is RFC-005 territory, but this is a lock-only bump that touches no harness code → no RFC conflict.

Tier 1: Fixes Required

None. Verification performed:

  • uv lock --check (opencode_env) → PASS ("Resolved 130 packages").
  • Hash integrity: all 46 locked cryptography-50.0.0 artifacts (1 sdist + 45 wheels) match PyPI sha256 + size + filename exactly; none yanked; no PyPI artifact missing from the lock; no non-cryptography files.pythonhosted.org line changed.
  • Correct as lock-only: cryptography is transitive (openenv → fastmcp → authlib → cryptography, also via joserfc, pyjwt[crypto], secretstorage); pyproject untouched; no requires-dist re-sync; no editable-openenv refresh.
  • Blast radius: no opencode_env source imports cryptography/authlib/jwt/secretstorage/keyring → zero env-code impact.
  • Stale check: origin/main == PR base (024eedc); git merge-tree clean; 1 commit ahead, no rebase needed.

Tier 2: Alignment Discussion

Principle Conflicts

ALIGNMENT FLAG: Lock index-source flip from the HF PyPI mirror to public PyPI

  • Principle at stake: PRINCIPLES.md L15/L22 — "Container isolation for reproducibility"; artifact provenance
  • The concern: this re-lock flips all 135 index sources from pypi.registries.huggingface.techpypi.org/simple (0 mirror refs remain; 0 → 135). Artifact URLs stay files.pythonhosted.org and all hashes are unchanged, so it is almost certainly benign — but it changes the declared provenance of every dependency, which is a team/reproducibility decision rather than something to silently accept in a bot bump. Do not self-revert — registry choice is a team call.
  • Suggested reviewer: @Darktex (reproducibility principle author) + @burtenshaw (dependabot config owner)

RFC Conflicts

None identified.

Process / heads-up notes (non-blocking)

  • exclude-paths bypass: .github/dependabot.yml configures the uv updater with directory: "/" + exclude-paths: ["envs/**"] (authored by @burtenshaw, 5f499da), yet this native PR modifies envs/opencode_env/uv.lock. Two compounding reasons it still fires: (1) the uv ecosystem doesn't honor exclude-paths (dependabot-core#15102), and (2) CVE-driven security updates can't be suppressed by exclude-paths at all (dependabot-core#14408). The codex/dependabot-envs-* aggregate roll-ups are the intended path for env bumps. cc @burtenshaw.
  • Lock revision = 2 → 3: latent-only. openenv-base:latest ships uv 0.5.27 (too old for rev-3) and this env's server/Dockerfile uses uv sync --frozen (only installs fresh uv if ! command -v uv, which won't trigger). Not exercised here — docker-build.yml triggers on envs/**/Dockerfile/*.py, not uv.lock — and several already-rev-3 envs (openapp/jupyter/…) deploy fine. Worth confirming the base image's uv can parse rev-3 eventually.

Summary

  • 0 mechanical issues to fix
  • 1 alignment point for human review (index-source provenance flip)
  • 0 RFC conflicts
  • Verdict: security-positive transitive bump (clears 4 distinct advisories, incl. one fixed only in 50.0.0); safe to proceed after a nod on the index-flip provenance.
Open in Web View Automation 

Sent by Cursor Automation: Pre-review

Comment thread envs/opencode_env/uv.lock
@@ -605,68 +605,65 @@ toml = [

[[package]]
name = "cryptography"
version = "47.0.0"
source = { registry = "https://pypi.registries.huggingface.tech/" }
version = "50.0.0"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security bump (positive). cryptography 47.0.0 → 50.0.0 clears all 4 distinct advisories outstanding at 47.0.0 (7 PyPI records incl. GHSA/PYSEC aliases):

Verified: all 46 locked 50.0.0 artifacts (1 sdist + 45 wheels) match PyPI sha256+size exactly, none yanked; 50.0.0 itself reports 0 advisories; requires_python >=3.9 satisfied by opencode_env >=3.10. Transitive via authlib/joserfc/pyjwt[crypto]/secretstorage — no opencode_env code imports it.

Comment thread envs/opencode_env/uv.lock
@@ -17,7 +17,7 @@ resolution-markers = [
[[package]]
name = "aiofile"
version = "3.9.0"
source = { registry = "https://pypi.registries.huggingface.tech/" }
source = { registry = "https://pypi.org/simple" }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tier 2 (reproducibility / provenance). This re-lock flips all 135 index sources from the HF mirror (pypi.registries.huggingface.tech) to public PyPI (pypi.org/simple) — 0 mirror refs remain. Artifact URLs stay files.pythonhosted.org and every hash is unchanged, so it's almost certainly benign, but it changes the declared provenance of the whole lock. Registry choice is a team decision → flagging for @Darktex + @burtenshaw; please don't self-revert in this PR.

Comment thread envs/opencode_env/uv.lock
@@ -1,5 +1,5 @@
version = 1
revision = 2
revision = 3

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Heads-up (non-blocking). Lock revision bumps 2 → 3, which needs uv ≥ ~0.8. openenv-base:latest ships uv 0.5.27 and this env's server/Dockerfile uses uv sync --frozen (only installs fresh uv if ! command -v uv, which won't trigger since the base has it). Not exercised by this PR (docker-build.yml triggers on Dockerfile/*.py, not uv.lock), and other rev-3 envs already deploy — but worth confirming the base image's uv can parse rev-3.

@burtenshaw

Copy link
Copy Markdown
Collaborator

Closing in favor of aggregate env Dependabot PR #1015.

@burtenshaw burtenshaw closed this Aug 6, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 6, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/uv/envs/opencode_env/cryptography-50.0.0 branch August 6, 2026 09:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Dependencies environment python:uv Pull requests that update python:uv code size: small Small pull request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant