Skip to content

chore(deps): bump cryptography from 49.0.0 to 50.0.0 in /envs/pelican_svg_env - #1066

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/envs/pelican_svg_env/cryptography-50.0.0
Closed

chore(deps): bump cryptography from 49.0.0 to 50.0.0 in /envs/pelican_svg_env#1066
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/envs/pelican_svg_env/cryptography-50.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 5, 2026

Copy link
Copy Markdown
Contributor

Bumps cryptography from 49.0.0 to 50.0.0.

Changelog

Sourced from cryptography's changelog.

50.0.0 - 2026-07-31


* **SECURITY ISSUE**:
  :func:`~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der`
  and its PEM and S/MIME variants no longer expose distinguishable errors or
  timing when unwrapping a ``RecipientInfo``'s ``encryptedKey``, which could
  act as a Bleichenbacher oracle for callers that decrypt untrusted messages.
  A random key is now substituted on failure, as described in :rfc:`3218`.
  Credit to **@X1AOxiang** for reporting the issue. **CVE-2026-69247**
* Deprecated Diffie-Hellman key exchange over finite fields (FFDH).
  Everything FFDH is deprecated, including the types in
  ``cryptography.hazmat.primitives.asymmetric.dh`` and loading FFDH keys or
  parameters with the key loading APIs. Users should migrate to a more
  modern key exchange algorithm.
* Added ``xof()`` class methods to
  :class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and
  :class:`~cryptography.hazmat.primitives.hashes.SHAKE256` for constructing
  algorithm instances configured for use with
  :class:`~cryptography.hazmat.primitives.hashes.XOFHash`.
* The :mod:`X.509 verification <cryptography.x509.verification>` APIs are now
  considered stable and are subject to our API stability policy.
* Added the :doc:`/cobblestone` recipe, an implementation of the
  Cobblestone-128 and Cobblestone-256 instantiations of the `C2SP
  chunked-encryption specification
  <https://c2sp.org/chunked-encryption>`_ for streaming authenticated
  encryption of large messages.
* Parsing a Signed Certificate Timestamp list now rejects encodings that
  carry trailing bytes after the list or after an individual SCT, instead of
  silently ignoring them.
* Added support for using :class:`~cryptography.x509.Name` as a field type in
  the :doc:`/hazmat/asn1/index` module.
* Loading a public key or an EC private key now rejects DER where the
  ``subjectPublicKey`` (or EC ``publicKey``) ``BIT STRING`` declares a non-zero
  number of unused bits, instead of silently ignoring it.
* Parsing a CRL entry's ``InvalidityDate`` extension now rejects a
  ``GeneralizedTime`` that carries fractional seconds or another non-DER form,
  matching the strict encoding already required for every other X.509 time
  field.
* :func:`~cryptography.x509.ocsp.load_der_ocsp_request` and
  :func:`~cryptography.x509.ocsp.load_der_ocsp_response` now reject a request
  or response whose ``version`` field is not ``v1``, the only version defined
  by RFC 6960, matching the version validation already performed when loading
  certificates, CSRs and CRLs.
* :class:`~cryptography.hazmat.primitives.hashes.XOFHash` is now supported
  when building against AWS-LC.
* HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when
  building against AWS-LC.
* Diffie-Hellman (:doc:`/hazmat/primitives/asymmetric/dh`) is now supported
  when building against AWS-LC.
</tr></table> 

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note

Low Risk
Lockfile-only transitive dependency bump with no direct cryptography usage in the env; main residual risk is rare breakage from stricter X.509 parsing in upstream libraries.

Overview
Updates the envs/pelican_svg_env uv lock so transitive cryptography moves from 49.0.0 to 50.0.0 (pulled in by dependencies such as Authlib). There are no application code or direct dependency declaration changes in this PR.

The new release includes a PKCS#7 decryption oracle fix (CVE-2026-69247) and tighter validation in several X.509/OCSP parsing paths; finite-field Diffie–Hellman APIs are deprecated in 50.x.

Reviewed by Cursor Bugbot for commit 43206d5. Bugbot is set up for automated code reviews on this repo. Configure here.

Bumps [cryptography](https://github.com/pyca/cryptography) from 49.0.0 to 50.0.0.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@49.0.0...50.0.0)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 50.0.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added Dependencies python:uv Pull requests that update python:uv code labels Aug 5, 2026
@bot-ci-comment

bot-ci-comment Bot commented Aug 5, 2026

Copy link
Copy Markdown

The docs for this PR live here. All of your documentation changes will be reflected on that endpoint. The docs are available until 30 days after the last update.

@burtenshaw burtenshaw added environment size: small Small pull request labels Aug 5, 2026 — with Cursor

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Alignment Review Report

Automated two-tier review of this Dependabot bump. Verdict: no mechanical fixes required, and no principle / invariant / RFC conflicts. The regenerated lockfile does change more than the title implies — a few non-blocking observations are noted for maintainer awareness.

Automated Checks

  • Lint (.claude/hooks/lint.sh): PASS for this PR. The PR changes 0 Python files (only envs/pelican_svg_env/uv.lock), and the lint pipeline only inspects .py files. The hook does surface pre-existing formatting drift in unrelated envs (opencode_env, pi_env, chat_env, README code fences, …), but none in pelican_svg_env and none attributable to this change.
  • Debug code (.claude/hooks/check-debug.sh): CLEAN for this PR. Findings are all pre-existing print(...)/docstring examples in src/ (e.g. mcp_client.py); the changed file contains no debug code.
  • Lockfile validity (uv lock --check in envs/pelican_svg_env): PASS — resolved 127 packages; the lock is consistent with pyproject.toml.
  • cryptography 50.0.0 artifacts: sdist + wheels resolve to canonical files.pythonhosted.org URLs with sha256 hashes (released 2026-07-31). All 143 registry-sourced packages download from pythonhosted.org with pinned hashes and the only non-registry entry is the local project itself (editable = "."), so there is no private-package / dependency-confusion vector. Routine, security-positive upgrade.

Open RFCs Context

RFCs 000–005 are In Review and RFC 010 is Draft. They concern core abstractions, MCP, rewards/rubrics, agentic harnesses, and world-modeling — none touch dependency management, lockfiles, or package indexes. No RFC surface area is affected by this change.

Tier 1: Fixes Required

None. No lint failures, debug code, uninitialized/type errors, missing imports, syntax errors, or security issues are attributable to this PR.

Tier 2: Alignment Discussion

Principle Conflicts

None identified. Nothing in PRINCIPLES.md (Gym-style API, container isolation, type safety, rewards-in-environment, agents-cannot-reset, MCP-as-standard, WebSocket step loop, one-env-one-trajectory) or INVARIANTS.md relates to dependency pinning.

RFC Conflicts

None identified.

(No alignment flags → no specific alignment reviewers required.)

Observations (non-blocking — maintainer awareness)

These are Dependabot regeneration artifacts, not defects:

  1. Index switch for all 143 packages: source flips from https://pypi.registries.huggingface.tech/https://pypi.org/simple. Artifact download URLs stay on files.pythonhosted.org in both cases, so provenance is unchanged — this is an index/metadata-source change only. However, 16 other env locks (chat_env, opencode_env, pi_env, …) still pin the internal HF index, so this introduces inconsistency. Worth a decision on whether Dependabot should preserve the internal index or whether all envs should migrate to public PyPI.
  2. Lock format revision = 23. Not a breakage risk here: CI uses uv 0.9.3 (supports revision 3) and qed_math_env is already on revision 3.
  3. Transitive-dependency markers simplified (e.g. secretstorage's cryptography/jeepney markers collapse to unconditional). Cosmetic resolver-representation change from the newer uv; uv lock --check confirms the result is consistent.

Summary

  • 0 mechanical issues to fix (Tier 1)
  • 0 alignment points for human review (Tier 2)
  • 0 RFC conflicts to discuss
  • 3 non-blocking observations about lockfile scope noted above.
Open in Web View Automation 

Sent by Cursor Automation: Pre-review

@@ -1,5 +1,5 @@
version = 1
revision = 2
revision = 3

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Non-blocking: the lock format revision bumps from 23 as a side effect of Dependabot regenerating this file with a newer uv. Not a breakage risk — CI pins uv 0.9.3 (which supports revision 3) and qed_math_env already uses revision 3. Flagging only because most other env locks are still on revision 2, so this is a deliberate-ish divergence worth being aware of.

version = "49.0.0"
source = { registry = "https://pypi.registries.huggingface.tech/" }
version = "50.0.0"
source = { registry = "https://pypi.org/simple" }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Non-blocking (representative of all 143 packages in this file): the resolution source switched from the internal https://pypi.registries.huggingface.tech/ index to public https://pypi.org/simple. The actual artifact URLs remain files.pythonhosted.org with pinned sha256 hashes, so download provenance/integrity is unchanged — this is an index/metadata-source change. 16 other env locks still pin the internal HF index, so this makes pelican_svg_env inconsistent with them. If preserving the internal index is intended, Dependabot may need an index/UV_INDEX_URL configuration so regenerations don't flip it back to public PyPI.

@burtenshaw

Copy link
Copy Markdown
Collaborator

Closing in favor of aggregate env Dependabot PR #1015.

@burtenshaw burtenshaw closed this Aug 6, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 6, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/uv/envs/pelican_svg_env/cryptography-50.0.0 branch August 6, 2026 09:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Dependencies environment python:uv Pull requests that update python:uv code size: small Small pull request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant