chore(deps): bump cryptography from 49.0.0 to 50.0.0 in /envs/pelican_svg_env - #1066
chore(deps): bump cryptography from 49.0.0 to 50.0.0 in /envs/pelican_svg_env#1066dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [cryptography](https://github.com/pyca/cryptography) from 49.0.0 to 50.0.0. - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@49.0.0...50.0.0) --- updated-dependencies: - dependency-name: cryptography dependency-version: 50.0.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
|
The docs for this PR live here. All of your documentation changes will be reflected on that endpoint. The docs are available until 30 days after the last update. |
There was a problem hiding this comment.
Alignment Review Report
Automated two-tier review of this Dependabot bump. Verdict: no mechanical fixes required, and no principle / invariant / RFC conflicts. The regenerated lockfile does change more than the title implies — a few non-blocking observations are noted for maintainer awareness.
Automated Checks
- Lint (
.claude/hooks/lint.sh): PASS for this PR. The PR changes 0 Python files (onlyenvs/pelican_svg_env/uv.lock), and the lint pipeline only inspects.pyfiles. The hook does surface pre-existing formatting drift in unrelated envs (opencode_env,pi_env,chat_env, README code fences, …), but none inpelican_svg_envand none attributable to this change. - Debug code (
.claude/hooks/check-debug.sh): CLEAN for this PR. Findings are all pre-existingprint(...)/docstring examples insrc/(e.g.mcp_client.py); the changed file contains no debug code. - Lockfile validity (
uv lock --checkinenvs/pelican_svg_env): PASS — resolved 127 packages; the lock is consistent withpyproject.toml. cryptography50.0.0 artifacts: sdist + wheels resolve to canonicalfiles.pythonhosted.orgURLs withsha256hashes (released 2026-07-31). All 143 registry-sourced packages download from pythonhosted.org with pinned hashes and the only non-registry entry is the local project itself (editable = "."), so there is no private-package / dependency-confusion vector. Routine, security-positive upgrade.
Open RFCs Context
RFCs 000–005 are In Review and RFC 010 is Draft. They concern core abstractions, MCP, rewards/rubrics, agentic harnesses, and world-modeling — none touch dependency management, lockfiles, or package indexes. No RFC surface area is affected by this change.
Tier 1: Fixes Required
None. No lint failures, debug code, uninitialized/type errors, missing imports, syntax errors, or security issues are attributable to this PR.
Tier 2: Alignment Discussion
Principle Conflicts
None identified. Nothing in PRINCIPLES.md (Gym-style API, container isolation, type safety, rewards-in-environment, agents-cannot-reset, MCP-as-standard, WebSocket step loop, one-env-one-trajectory) or INVARIANTS.md relates to dependency pinning.
RFC Conflicts
None identified.
(No alignment flags → no specific alignment reviewers required.)
Observations (non-blocking — maintainer awareness)
These are Dependabot regeneration artifacts, not defects:
- Index switch for all 143 packages:
sourceflips fromhttps://pypi.registries.huggingface.tech/→https://pypi.org/simple. Artifact download URLs stay onfiles.pythonhosted.orgin both cases, so provenance is unchanged — this is an index/metadata-source change only. However, 16 other env locks (chat_env,opencode_env,pi_env, …) still pin the internal HF index, so this introduces inconsistency. Worth a decision on whether Dependabot should preserve the internal index or whether all envs should migrate to public PyPI. - Lock format
revision = 2→3. Not a breakage risk here: CI usesuv 0.9.3(supports revision 3) andqed_math_envis already on revision 3. - Transitive-dependency markers simplified (e.g.
secretstorage'scryptography/jeepneymarkers collapse to unconditional). Cosmetic resolver-representation change from the newer uv;uv lock --checkconfirms the result is consistent.
Summary
- 0 mechanical issues to fix (Tier 1)
- 0 alignment points for human review (Tier 2)
- 0 RFC conflicts to discuss
- 3 non-blocking observations about lockfile scope noted above.
Sent by Cursor Automation: Pre-review
| @@ -1,5 +1,5 @@ | |||
| version = 1 | |||
| revision = 2 | |||
| revision = 3 | |||
There was a problem hiding this comment.
Non-blocking: the lock format revision bumps from 2 → 3 as a side effect of Dependabot regenerating this file with a newer uv. Not a breakage risk — CI pins uv 0.9.3 (which supports revision 3) and qed_math_env already uses revision 3. Flagging only because most other env locks are still on revision 2, so this is a deliberate-ish divergence worth being aware of.
| version = "49.0.0" | ||
| source = { registry = "https://pypi.registries.huggingface.tech/" } | ||
| version = "50.0.0" | ||
| source = { registry = "https://pypi.org/simple" } |
There was a problem hiding this comment.
Non-blocking (representative of all 143 packages in this file): the resolution source switched from the internal https://pypi.registries.huggingface.tech/ index to public https://pypi.org/simple. The actual artifact URLs remain files.pythonhosted.org with pinned sha256 hashes, so download provenance/integrity is unchanged — this is an index/metadata-source change. 16 other env locks still pin the internal HF index, so this makes pelican_svg_env inconsistent with them. If preserving the internal index is intended, Dependabot may need an index/UV_INDEX_URL configuration so regenerations don't flip it back to public PyPI.
|
Closing in favor of aggregate env Dependabot PR #1015. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |


Bumps cryptography from 49.0.0 to 50.0.0.
Changelog
Sourced from cryptography's changelog.
... (truncated)
Commits
dcb7050Prepare for 50.0.0 release (#15372)53fccd9Don't leak how PKCS#7 encryptedKey decryption failed (#15369)d472f97Addfrom __future__ import annotationsto all src/ Python files (#15371)908773dBump downstream dependencies in CI (#15368)2cc07ccBump BoringSSL, OpenSSL, AWS-LC in CI (#15367)c94ede9chore(deps): bump ruff from 0.16.0 to 0.16.1 (#15366)67a8308chore(deps): bump virtualenv from 21.7.0 to 21.7.1 (#15365)95018ffRelease the GIL in one-shot AEAD encrypt/decrypt (#15361)6954733Release the GIL during DH and DSA parameter generation (#15364)6893b94Import _serialization instead of serialization in x509/extensions (#15363)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.
Note
Low Risk
Lockfile-only transitive dependency bump with no direct cryptography usage in the env; main residual risk is rare breakage from stricter X.509 parsing in upstream libraries.
Overview
Updates the
envs/pelican_svg_envuv lock so transitivecryptographymoves from 49.0.0 to 50.0.0 (pulled in by dependencies such as Authlib). There are no application code or direct dependency declaration changes in this PR.The new release includes a PKCS#7 decryption oracle fix (CVE-2026-69247) and tighter validation in several X.509/OCSP parsing paths; finite-field Diffie–Hellman APIs are deprecated in 50.x.
Reviewed by Cursor Bugbot for commit 43206d5. Bugbot is set up for automated code reviews on this repo. Configure here.