Skip to content

deps: Bump cryptography from 49.0.0 to 50.0.0 - #59

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/cryptography-50.0.0
Closed

deps: Bump cryptography from 49.0.0 to 50.0.0#59
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/cryptography-50.0.0

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 3, 2026

Copy link
Copy Markdown
Contributor

Bumps cryptography from 49.0.0 to 50.0.0.

Changelog

Sourced from cryptography's changelog.

50.0.0 - 2026-07-31


* **SECURITY ISSUE**:
:func:`~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der`
and its PEM and S/MIME variants no longer expose distinguishable errors or
timing when unwrapping a ``RecipientInfo``'s ``encryptedKey``, which could
act as a Bleichenbacher oracle for callers that decrypt untrusted messages.
A random key is now substituted on failure, as described in :rfc:`3218`.
Credit to **@X1AOxiang** for reporting the issue
* Deprecated Diffie-Hellman key exchange over finite fields (FFDH).
Everything FFDH is deprecated, including the types in
``cryptography.hazmat.primitives.asymmetric.dh`` and loading FFDH keys or
parameters with the key loading APIs. Users should migrate to a more
modern key exchange algorithm.
* Added ``xof()`` class methods to
:class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and
:class:`~cryptography.hazmat.primitives.hashes.SHAKE256` for constructing
algorithm instances configured for use with
:class:`~cryptography.hazmat.primitives.hashes.XOFHash`.
* The :mod:`X.509 verification <cryptography.x509.verification>` APIs are now
considered stable and are subject to our API stability policy.
* Added the :doc:`/cobblestone` recipe, an implementation of the
Cobblestone-128 and Cobblestone-256 instantiations of the `C2SP
chunked-encryption specification
<https://c2sp.org/chunked-encryption>`_ for streaming authenticated
encryption of large messages.
* Parsing a Signed Certificate Timestamp list now rejects encodings that
carry trailing bytes after the list or after an individual SCT, instead of
silently ignoring them.
* Added support for using :class:`~cryptography.x509.Name` as a field type in
the :doc:`/hazmat/asn1/index` module.
* Loading a public key or an EC private key now rejects DER where the
``subjectPublicKey`` (or EC ``publicKey``) ``BIT STRING`` declares a non-zero
number of unused bits, instead of silently ignoring it.
* Parsing a CRL entry's ``InvalidityDate`` extension now rejects a
``GeneralizedTime`` that carries fractional seconds or another non-DER form,
matching the strict encoding already required for every other X.509 time
field.
* :func:`~cryptography.x509.ocsp.load_der_ocsp_request` and
:func:`~cryptography.x509.ocsp.load_der_ocsp_response` now reject a request
or response whose ``version`` field is not ``v1``, the only version defined
by RFC 6960, matching the version validation already performed when loading
certificates, CSRs and CRLs.
* :class:`~cryptography.hazmat.primitives.hashes.XOFHash` is now supported
when building against AWS-LC.
* HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when
building against AWS-LC.
* Diffie-Hellman (:doc:`/hazmat/primitives/asymmetric/dh`) is now supported
when building against AWS-LC.
</tr></table> 

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [cryptography](https://github.com/pyca/cryptography) from 49.0.0 to 50.0.0.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@49.0.0...50.0.0)
---
updated-dependencies:
- dependency-name: cryptography
dependency-version: 50.0.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Aug 3, 2026
rustyconover added a commit that referenced this pull request Aug 5, 2026
Folds in the three open Dependabot PRs:
- #45 GitHub Actions: astral-sh/setup-uv v8.2.0 -> v9.0.0,
docker/setup-buildx-action v3 -> v4, docker/login-action v3 -> v4,
docker/build-push-action v6 -> v7
- #59 cryptography 49.0.0 -> 50.0.0
- #60 the python-minor-and-patch group (typer, platformdirs, duckdb,
numpy, sqlglot, mypy, ruff, ty, mkdocs-material, pymdown-extensions)
The lock is a full `uv lock --upgrade`, so it lands a superset of what the
individual PRs proposed. vgi-rpc stays pinned at 0.39.1.
Two CI failures already red on main are fixed alongside:
- Docs (strict): `Worker.resolve_token` linked `[`TokenIdentity`][]`, whose
canonical path is a private vgi-rpc module griffe cannot resolve
statically. Demoted to a code span and documented what the type is in
docs/api/auth.md instead of pointing autorefs at a target that cannot exist.
- Windows (3.13 and 3.14): the `resolve_token` example in CLAUDE.md carried an
em dash in a comment. pytest_examples pipes example source to ruff with
`universal_newlines=True`, which encodes via the locale codec — cp1252 on
Windows — and ruff then rejects the stream as invalid UTF-8. Replaced with
ASCII. The other non-ASCII doc examples are outside DOC_FILES or marked
`# illustrative`, so they are never linted.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@rustyconover

Copy link
Copy Markdown
Contributor

Superseded by 494161c on main, which lands a full uv lock --upgrade (a superset of this PR) together with the GitHub Actions bumps. Released as 0.25.1.

@dependabot@github

dependabotBot commented on behalf of githubAug 5, 2026

Copy link
Copy Markdown
ContributorAuthor

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabotBot deleted the dependabot/uv/cryptography-50.0.0 branch August 5, 2026 13:07
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filepython:uvPull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@rustyconover