Skip to content

build(deps-dev): update cryptography requirement from >=49.0.0 to >=50.0.1 - #95

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/pip/cryptography-gte-50.0.1
Aug 31, 2026
Merged

build(deps-dev): update cryptography requirement from >=49.0.0 to >=50.0.1#95
github-actions[bot] merged 1 commit into
mainfrom
dependabot/pip/cryptography-gte-50.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 31, 2026

Copy link
Copy Markdown
Contributor

User description

Updates the requirements on cryptography to permit the latest version.

Changelog

Sourced from cryptography's changelog.

50.0.1 - 2026-08-25


* Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.2.

.. _v50-0-0:

50.0.0 - 2026-07-31

  • SECURITY ISSUE: :func:~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der and its PEM and S/MIME variants no longer expose distinguishable errors or timing when unwrapping a RecipientInfo's encryptedKey, which could act as a Bleichenbacher oracle for callers that decrypt untrusted messages. A random key is now substituted on failure, as described in :rfc:3218. Credit to @​X1AOxiang for reporting the issue. CVE-2026-69247
  • Deprecated Diffie-Hellman key exchange over finite fields (FFDH). Everything FFDH is deprecated, including the types in cryptography.hazmat.primitives.asymmetric.dh and loading FFDH keys or parameters with the key loading APIs. Users should migrate to a more modern key exchange algorithm.
  • Added xof() class methods to :class:~cryptography.hazmat.primitives.hashes.SHAKE128 and :class:~cryptography.hazmat.primitives.hashes.SHAKE256 for constructing algorithm instances configured for use with :class:~cryptography.hazmat.primitives.hashes.XOFHash.
  • The :mod:X.509 verification <cryptography.x509.verification> APIs are now considered stable and are subject to our API stability policy.
  • Added the :doc:/cobblestone recipe, an implementation of the Cobblestone-128 and Cobblestone-256 instantiations of the C2SP chunked-encryption specification <https://c2sp.org/chunked-encryption>_ for streaming authenticated encryption of large messages.
  • Parsing a Signed Certificate Timestamp list now rejects encodings that carry trailing bytes after the list or after an individual SCT, instead of silently ignoring them.
  • Added support for using :class:~cryptography.x509.Name as a field type in the :doc:/hazmat/asn1/index module.
  • Loading a public key or an EC private key now rejects DER where the subjectPublicKey (or EC publicKey) BIT STRING declares a non-zero number of unused bits, instead of silently ignoring it.
  • Parsing a CRL entry's InvalidityDate extension now rejects a GeneralizedTime that carries fractional seconds or another non-DER form, matching the strict encoding already required for every other X.509 time field.
  • :func:~cryptography.x509.ocsp.load_der_ocsp_request and :func:~cryptography.x509.ocsp.load_der_ocsp_response now reject a request or response whose version field is not v1, the only version defined by RFC 6960, matching the version validation already performed when loading

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

PR Type

Other


Description

  • Update cryptography requirement from >=49.0.0 to >=50.0.1

  • Applied to both cloud and all optional dependency groups


Diagram Walkthrough

flowchart LR
  A["pyproject.toml deps"] -- "bump cryptography" --> B["cloud extra: >=50.0.1"]
  A -- "bump cryptography" --> C["all extra: >=50.0.1"]
Loading

File Walkthrough

Relevant files
Dependencies
pyproject.toml
Bump cryptography requirement to >=50.0.1                               

pyproject.toml

  • Updated cryptography minimum version in the cloud optional
    dependencies from >=49.0.0 to >=50.0.1
  • Updated cryptography minimum version in the all optional dependencies
    group from >=49.0.0 to >=50.0.1
+2/-2     

Updates the requirements on [cryptography](https://github.com/pyca/cryptography) to permit the latest version.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@49.0.0...50.0.1)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 50.0.1
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Aug 31, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Approved by Dependabot Autopilot.

@github-actions
github-actions Bot enabled auto-merge (squash) August 31, 2026 05:35
@github-actions

Copy link
Copy Markdown

🤖 Autonomous PR Agent Review

📊 Change Overview

  • Files Changed: 1
  • Lines Added: +2
  • Lines Deleted: -2
  • Triage Size: size/S

📁 Modified Files (Top 10)

  • pyproject.toml (+2/-2)

🛡️ Security & Quality Assessment

  • ✅ No hardcoded secrets or suspicious debugging statements detected.

✅ Recommendation

  • All automated checks initiated. Ensure CI builds pass before merging.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Approved by Dependabot Autopilot.

@rudra-pr-agent

Copy link
Copy Markdown

PR Reviewer Guide 🔍

Here are some key observations to aid the review process:

🎫 Ticket compliance analysis 🔶

7 - Partially compliant

Compliant requirements:

  • typer requirement already permits >=0.24.1 (pyproject.toml pins typer>=0.27.1), though this was not changed by this PR.

Non-compliant requirements:

  • This PR does not touch the typer requirement at all; it updates the cryptography requirement instead, so it does not implement the ticket's change.

Requires further human verification:

  • Confirm whether the linked ticket (typer update) is the correct ticket for this cryptography dependency bump, or if the wrong ticket was attached.
⏱️ Estimated effort to review: 1 🔵⚪⚪⚪⚪
🧪 No relevant tests
🔒 No security concerns identified
⚡ No major issues detected

@rudra-pr-agent

Copy link
Copy Markdown

PR Code Suggestions ✨

No code suggestions found for the PR.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Approved by Dependabot Autopilot.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Approved by Dependabot Autopilot.

@github-actions
github-actions Bot merged commit ceed39d into main Aug 31, 2026
17 checks passed
@dependabot
dependabot Bot deleted the dependabot/pip/cryptography-gte-50.0.1 branch August 31, 2026 05:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

config dependencies Pull requests that update a dependency file python Pull requests that update python code Review effort 1/5 size/S

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants