Skip to content

chore(deps): bump cryptography from 48.0.1 to 50.0.0 in /envs/sophistry_bench_sprint_env - #1065

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/envs/sophistry_bench_sprint_env/cryptography-50.0.0
Closed

chore(deps): bump cryptography from 48.0.1 to 50.0.0 in /envs/sophistry_bench_sprint_env#1065
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/envs/sophistry_bench_sprint_env/cryptography-50.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 5, 2026

Copy link
Copy Markdown
Contributor

Bumps cryptography from 48.0.1 to 50.0.0.

Changelog

Sourced from cryptography's changelog.

50.0.0 - 2026-07-31


* **SECURITY ISSUE**:
  :func:`~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der`
  and its PEM and S/MIME variants no longer expose distinguishable errors or
  timing when unwrapping a ``RecipientInfo``'s ``encryptedKey``, which could
  act as a Bleichenbacher oracle for callers that decrypt untrusted messages.
  A random key is now substituted on failure, as described in :rfc:`3218`.
  Credit to **@X1AOxiang** for reporting the issue. **CVE-2026-69247**
* Deprecated Diffie-Hellman key exchange over finite fields (FFDH).
  Everything FFDH is deprecated, including the types in
  ``cryptography.hazmat.primitives.asymmetric.dh`` and loading FFDH keys or
  parameters with the key loading APIs. Users should migrate to a more
  modern key exchange algorithm.
* Added ``xof()`` class methods to
  :class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and
  :class:`~cryptography.hazmat.primitives.hashes.SHAKE256` for constructing
  algorithm instances configured for use with
  :class:`~cryptography.hazmat.primitives.hashes.XOFHash`.
* The :mod:`X.509 verification <cryptography.x509.verification>` APIs are now
  considered stable and are subject to our API stability policy.
* Added the :doc:`/cobblestone` recipe, an implementation of the
  Cobblestone-128 and Cobblestone-256 instantiations of the `C2SP
  chunked-encryption specification
  <https://c2sp.org/chunked-encryption>`_ for streaming authenticated
  encryption of large messages.
* Parsing a Signed Certificate Timestamp list now rejects encodings that
  carry trailing bytes after the list or after an individual SCT, instead of
  silently ignoring them.
* Added support for using :class:`~cryptography.x509.Name` as a field type in
  the :doc:`/hazmat/asn1/index` module.
* Loading a public key or an EC private key now rejects DER where the
  ``subjectPublicKey`` (or EC ``publicKey``) ``BIT STRING`` declares a non-zero
  number of unused bits, instead of silently ignoring it.
* Parsing a CRL entry's ``InvalidityDate`` extension now rejects a
  ``GeneralizedTime`` that carries fractional seconds or another non-DER form,
  matching the strict encoding already required for every other X.509 time
  field.
* :func:`~cryptography.x509.ocsp.load_der_ocsp_request` and
  :func:`~cryptography.x509.ocsp.load_der_ocsp_response` now reject a request
  or response whose ``version`` field is not ``v1``, the only version defined
  by RFC 6960, matching the version validation already performed when loading
  certificates, CSRs and CRLs.
* :class:`~cryptography.hazmat.primitives.hashes.XOFHash` is now supported
  when building against AWS-LC.
* HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when
  building against AWS-LC.
* Diffie-Hellman (:doc:`/hazmat/primitives/asymmetric/dh`) is now supported
  when building against AWS-LC.
</tr></table> 

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note

Low Risk
Lockfile-only dependency bump for a bench env; main risk is upstream major-version behavior changes in crypto/X.509 if that env exercises those APIs.

Overview
Bumps the locked cryptography package from 48.0.1 to 50.0.0 in envs/sophistry_bench_sprint_env (via uv.lock). It is pulled in transitively (e.g. through Authlib), not as a direct project dependency.

The upgrade is a major release and includes a security fix for PKCS#7 encryptedKey decryption (CVE-2026-69247), plus stricter X.509/OCSP parsing and other library changes described in the upstream changelog. No application source in this repo is modified—only the environment lockfile.

Reviewed by Cursor Bugbot for commit 660ad70. Bugbot is set up for automated code reviews on this repo. Configure here.

Bumps [cryptography](https://github.com/pyca/cryptography) from 48.0.1 to 50.0.0.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@48.0.1...50.0.0)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 50.0.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added Dependencies python:uv Pull requests that update python:uv code labels Aug 5, 2026
@burtenshaw burtenshaw added environment size: small Small pull request labels Aug 5, 2026 — with Cursor
@bot-ci-comment

bot-ci-comment Bot commented Aug 5, 2026

Copy link
Copy Markdown

The docs for this PR live here. All of your documentation changes will be reflected on that endpoint. The docs are available until 30 days after the last update.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Alignment Review Report

Two-tier automated review of this Dependabot bump. Scope: the PR touches exactly one file — envs/sophistry_bench_sprint_env/uv.lock (no .py, pyproject.toml, openenv.yaml, or Dockerfile changes). Only one package version actually changes: cryptography 48.0.1 → 50.0.0.

Automated Checks

  • Lint (.claude/hooks/lint.sh): FAIL — but pre-existing and unrelated to this PR. The failures are ruff format diffs in ~26 files across other envs (e.g. opencode_env, pi_env, chat_env, coding_tools_env, jupyter_env, repl_env, terminus_env, textarena_env, agent_world_model_env). Nothing under sophistry_bench_sprint_env/ and nothing in this diff is implicated.
  • Debug code (.claude/hooks/check-debug.sh): FOUND — but all in src/openenv/** (docstring examples, Rich console output, a standalone test_local_docker_provider.py, and 3 pre-existing TODOs). None are in this diff.

Net: this PR introduces zero new lint or debug issues.

Open RFCs Context

RFCs 000/001/002/003/005 are In Review, 010 is Draft, and 004 has no status line. None govern Python dependency management, PyPI index selection, or lockfiles (RFC 002's "Dependency Management" section is about Docker Compose sim/prod, and its "registry" references are to container/tool registries). No RFC is in scope for this change.

Tier 1: Fixes Required

None attributable to this PR. The lint/debug findings above reflect pre-existing repo state; fixing them inside a lockfile-only Dependabot bump would be scope creep.

Tier 2: Alignment Discussion

Principle Conflicts

ALIGNMENT FLAG: Lockfile-wide package index switch (HF internal registry → public PyPI)

  • Principle/Invariant at stake: PRINCIPLES.md → "Container isolation for reproducibility and security"; INVARIANTS.md → Security Invariants ("Network access must be explicitly configured").
  • The concern: Beyond the intended cryptography bump, this regeneration flips the source registry for all 166 packages from https://pypi.registries.huggingface.tech/ to https://pypi.org/simple, and bumps the lock revision 2 → 3. This is almost certainly a side effect of Dependabot resolving without the HF internal index configured, rather than an intentional decision. Integrity risk is low here (every wheel/sdist keeps a pinned sha256 and artifact URLs remain files.pythonhosted.org), but it does change this env's resolution source of truth and will churn back on the next in-infra uv lock. Note the repo is already split (~16 envs on the HF registry, ~22 on pypi.org — including the reference echo_env), so pypi.org may be perfectly acceptable; the team should just confirm the intended index for sophistry_bench_sprint_env and, if HF is intended, ensure Dependabot is configured with it.
  • Suggested reviewer: @Darktex (git blame attributes both the security invariants and the container-isolation principle to them) — plus the env owner (added in #787).

RFC Conflicts

None identified.

Summary

  • 0 mechanical issues to fix (from this PR)
  • 1 alignment point for human review (whole-lockfile index/registry churn)
  • 0 RFC conflicts

FYI (security-positive, not a blocker): cryptography 50.0.0 (released 2026-07-31) patches CVE-2026-69247 — a Bleichenbacher oracle in PKCS#7 decryption affecting >=44.0.0,<50.0.0, i.e. the current 48.0.1 is vulnerable. It is a major jump (48 → 50) that deprecates FFDH; uv resolved it cleanly against the transitive consumers (authlib, joserfc, secretstorage), so there is no constraint break — a green CI run is the only runtime caveat before merge.

Open in Web View Automation 

Sent by Cursor Automation: Pre-review

@@ -849,68 +849,65 @@ toml = [

[[package]]
name = "cryptography"
version = "48.0.1"
source = { registry = "https://pypi.registries.huggingface.tech/" }
version = "50.0.0"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Intended change. cryptography 50.0.0 (released 2026-07-31) patches CVE-2026-69247 (a Bleichenbacher oracle in PKCS#7 decryption; affected range >=44.0.0,<50.0.0, so the prior 48.0.1 was vulnerable) — so this is security-positive. It is a major bump (deprecates FFDH over finite fields). uv resolved it against the transitive consumers (authlib, joserfc, secretstorage) with no constraint break, so a green CI run before merge is the only runtime caveat.

version = "48.0.1"
source = { registry = "https://pypi.registries.huggingface.tech/" }
version = "50.0.0"
source = { registry = "https://pypi.org/simple" }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tier 2 (alignment) — flagging for discussion, not a blocker: this line is one of 166 packages whose source flips from pypi.registries.huggingface.techpypi.org/simple in this regeneration (alongside revision 2 → 3). The whole lockfile's package index changed, not just cryptography. This is almost certainly a Dependabot side effect (it resolved without the HF internal index configured). Integrity is still protected (pinned sha256 + files.pythonhosted.org artifact URLs), but please confirm the intended index for this env; if the HF registry is intended, Dependabot needs it configured or this will churn back on the next in-infra uv lock. cc @Darktex

@burtenshaw

Copy link
Copy Markdown
Collaborator

Closing in favor of aggregate env Dependabot PR #1015.

@burtenshaw burtenshaw closed this Aug 6, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 6, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/uv/envs/sophistry_bench_sprint_env/cryptography-50.0.0 branch August 6, 2026 09:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Dependencies environment python:uv Pull requests that update python:uv code size: small Small pull request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant