Skip to content

Bump version to 2.11.3 - #397

Merged
thibauult merged 1 commit into
finos:mainfrom
matthewcummings:bump-version-to-2.11.3
Aug 26, 2026
Merged

Bump version to 2.11.3#397
thibauult merged 1 commit into
finos:mainfrom
matthewcummings:bump-version-to-2.11.3

Conversation

@matthewcummings

Copy link
Copy Markdown
Contributor

Summary

Bumps the version in pyproject.toml from 2.11.2 to 2.11.3 to prepare a patch release.

Context

The cryptography cap on the latest published release (v2.11.2) is ^46.0.0, which does not include the fix for CVE-2026-34180 (DoS via malformed ASN.1 input, patched in cryptography 48.0.1). Bots that depend on symphony-bdk-python cannot pin cryptography>=48.0.1 themselves because pip resolution fails against the transitive cap declared in BDK's own metadata.

The actual fix has already been merged to main via #390cryptography is now pinned to >=48.0.1,<49.0.0 and poetry.lock is regenerated accordingly. All that's missing to unblock downstream consumers is a published release cut from main.

This PR is just the version bump so that once merged, a maintainer can publish a GitHub Release tagged v2.11.3 and the existing release.yml workflow picks it up and pushes to PyPI.

Downstream impact

This unblocks CVE remediation on every downstream Symphony bot that depends on symphony-bdk-python — Symphony's InfoSec team is currently tracking the vulnerability across multiple bot deployments and the only unblock is a new release.

Test plan

  • Verified pyproject.toml version field is the only change.
  • After merge, a maintainer publishes a v2.11.3 GitHub Release from main.
  • release.yml fires, poetry publish --build pushes symphony_bdk_python-2.11.3 to PyPI.
  • Downstream bots pin symphony-bdk-python>=2.11.3 and verify pip install pulls cryptography 48.0.1.

Prepares a patch release so consumers can pull the cryptography>=48.0.1
constraint already merged to main via finos#390, closing CVE-2026-34180 on
downstream Symphony bots that depend on symphony-bdk-python.
@linux-foundation-easycla

linux-foundation-easyclaBot commented Aug 23, 2026

Copy link
Copy Markdown

CLA Signed
The committers listed above are authorized under a signed CLA.

  • ✅ login: matthewcummings / name: Matthew Cummings (e757da8)

@thibauult
thibauult merged commit 57aef93 into finos:mainAug 26, 2026
21 checks passed
matthewcummings added a commit to matthewcummings/symphony-bdk-python that referenced this pull request Aug 30, 2026
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. finos#397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
matthewcummings added a commit to matthewcummings/symphony-bdk-python that referenced this pull request Aug 30, 2026
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
matthewcummings added a commit that referenced this pull request Aug 31, 2026
* Raise cryptography ceiling to allow the patched 50.x
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. #397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
* Bump version to 2.11.4 to prepare a patch release
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in #390 sat unreleased for five days because the
version bump was a separate change (#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as #397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@matthewcummings@thibauult
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Bump version to 2.11.3 by matthewcummings · Pull Request #397 · finos/symphony-bdk-python · GitHub
Skip to content

Bump version to 2.11.3 - #397

Merged
thibauult merged 1 commit into
finos:mainfrom
matthewcummings:bump-version-to-2.11.3
Aug 26, 2026
Merged

Bump version to 2.11.3#397
thibauult merged 1 commit into
finos:mainfrom
matthewcummings:bump-version-to-2.11.3

Conversation

@matthewcummings

Copy link
Copy Markdown
Contributor

Summary

Bumps the version in pyproject.toml from 2.11.2 to 2.11.3 to prepare a patch release.

Context

The cryptography cap on the latest published release (v2.11.2) is ^46.0.0, which does not include the fix for CVE-2026-34180 (DoS via malformed ASN.1 input, patched in cryptography 48.0.1). Bots that depend on symphony-bdk-python cannot pin cryptography>=48.0.1 themselves because pip resolution fails against the transitive cap declared in BDK's own metadata.

The actual fix has already been merged to main via #390cryptography is now pinned to >=48.0.1,<49.0.0 and poetry.lock is regenerated accordingly. All that's missing to unblock downstream consumers is a published release cut from main.

This PR is just the version bump so that once merged, a maintainer can publish a GitHub Release tagged v2.11.3 and the existing release.yml workflow picks it up and pushes to PyPI.

Downstream impact

This unblocks CVE remediation on every downstream Symphony bot that depends on symphony-bdk-python — Symphony's InfoSec team is currently tracking the vulnerability across multiple bot deployments and the only unblock is a new release.

Test plan

  • Verified pyproject.toml version field is the only change.
  • After merge, a maintainer publishes a v2.11.3 GitHub Release from main.
  • release.yml fires, poetry publish --build pushes symphony_bdk_python-2.11.3 to PyPI.
  • Downstream bots pin symphony-bdk-python>=2.11.3 and verify pip install pulls cryptography 48.0.1.

Prepares a patch release so consumers can pull the cryptography>=48.0.1
constraint already merged to main via finos#390, closing CVE-2026-34180 on
downstream Symphony bots that depend on symphony-bdk-python.
@linux-foundation-easycla

linux-foundation-easyclaBot commented Aug 23, 2026

Copy link
Copy Markdown

CLA Signed
The committers listed above are authorized under a signed CLA.

  • ✅ login: matthewcummings / name: Matthew Cummings (e757da8)

@thibauult
thibauult merged commit 57aef93 into finos:mainAug 26, 2026
21 checks passed
matthewcummings added a commit to matthewcummings/symphony-bdk-python that referenced this pull request Aug 30, 2026
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. finos#397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
matthewcummings added a commit to matthewcummings/symphony-bdk-python that referenced this pull request Aug 30, 2026
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
matthewcummings added a commit that referenced this pull request Aug 31, 2026
* Raise cryptography ceiling to allow the patched 50.x
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. #397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
* Bump version to 2.11.4 to prepare a patch release
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in #390 sat unreleased for five days because the
version bump was a separate change (#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as #397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@matthewcummings@thibauult
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Bump version to 2.11.3 by matthewcummings · Pull Request #397 · finos/symphony-bdk-python · GitHub
Skip to content

Bump version to 2.11.3 - #397

Merged
thibauult merged 1 commit into
finos:mainfrom
matthewcummings:bump-version-to-2.11.3
Aug 26, 2026
Merged

Bump version to 2.11.3#397
thibauult merged 1 commit into
finos:mainfrom
matthewcummings:bump-version-to-2.11.3

Conversation

@matthewcummings

Copy link
Copy Markdown
Contributor

Summary

Bumps the version in pyproject.toml from 2.11.2 to 2.11.3 to prepare a patch release.

Context

The cryptography cap on the latest published release (v2.11.2) is ^46.0.0, which does not include the fix for CVE-2026-34180 (DoS via malformed ASN.1 input, patched in cryptography 48.0.1). Bots that depend on symphony-bdk-python cannot pin cryptography>=48.0.1 themselves because pip resolution fails against the transitive cap declared in BDK's own metadata.

The actual fix has already been merged to main via #390cryptography is now pinned to >=48.0.1,<49.0.0 and poetry.lock is regenerated accordingly. All that's missing to unblock downstream consumers is a published release cut from main.

This PR is just the version bump so that once merged, a maintainer can publish a GitHub Release tagged v2.11.3 and the existing release.yml workflow picks it up and pushes to PyPI.

Downstream impact

This unblocks CVE remediation on every downstream Symphony bot that depends on symphony-bdk-python — Symphony's InfoSec team is currently tracking the vulnerability across multiple bot deployments and the only unblock is a new release.

Test plan

  • Verified pyproject.toml version field is the only change.
  • After merge, a maintainer publishes a v2.11.3 GitHub Release from main.
  • release.yml fires, poetry publish --build pushes symphony_bdk_python-2.11.3 to PyPI.
  • Downstream bots pin symphony-bdk-python>=2.11.3 and verify pip install pulls cryptography 48.0.1.

Prepares a patch release so consumers can pull the cryptography>=48.0.1
constraint already merged to main via finos#390, closing CVE-2026-34180 on
downstream Symphony bots that depend on symphony-bdk-python.
@linux-foundation-easycla

linux-foundation-easyclaBot commented Aug 23, 2026

Copy link
Copy Markdown

CLA Signed
The committers listed above are authorized under a signed CLA.

  • ✅ login: matthewcummings / name: Matthew Cummings (e757da8)

@thibauult
thibauult merged commit 57aef93 into finos:mainAug 26, 2026
21 checks passed
matthewcummings added a commit to matthewcummings/symphony-bdk-python that referenced this pull request Aug 30, 2026
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. finos#397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
matthewcummings added a commit to matthewcummings/symphony-bdk-python that referenced this pull request Aug 30, 2026
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
matthewcummings added a commit that referenced this pull request Aug 31, 2026
* Raise cryptography ceiling to allow the patched 50.x
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. #397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
* Bump version to 2.11.4 to prepare a patch release
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in #390 sat unreleased for five days because the
version bump was a separate change (#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as #397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@matthewcummings@thibauult
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Bump version to 2.11.3 by matthewcummings · Pull Request #397 · finos/symphony-bdk-python · GitHub
Skip to content

Bump version to 2.11.3 - #397

Merged
thibauult merged 1 commit into
finos:mainfrom
matthewcummings:bump-version-to-2.11.3
Aug 26, 2026
Merged

Bump version to 2.11.3#397
thibauult merged 1 commit into
finos:mainfrom
matthewcummings:bump-version-to-2.11.3

Conversation

@matthewcummings

Copy link
Copy Markdown
Contributor

Summary

Bumps the version in pyproject.toml from 2.11.2 to 2.11.3 to prepare a patch release.

Context

The cryptography cap on the latest published release (v2.11.2) is ^46.0.0, which does not include the fix for CVE-2026-34180 (DoS via malformed ASN.1 input, patched in cryptography 48.0.1). Bots that depend on symphony-bdk-python cannot pin cryptography>=48.0.1 themselves because pip resolution fails against the transitive cap declared in BDK's own metadata.

The actual fix has already been merged to main via #390cryptography is now pinned to >=48.0.1,<49.0.0 and poetry.lock is regenerated accordingly. All that's missing to unblock downstream consumers is a published release cut from main.

This PR is just the version bump so that once merged, a maintainer can publish a GitHub Release tagged v2.11.3 and the existing release.yml workflow picks it up and pushes to PyPI.

Downstream impact

This unblocks CVE remediation on every downstream Symphony bot that depends on symphony-bdk-python — Symphony's InfoSec team is currently tracking the vulnerability across multiple bot deployments and the only unblock is a new release.

Test plan

  • Verified pyproject.toml version field is the only change.
  • After merge, a maintainer publishes a v2.11.3 GitHub Release from main.
  • release.yml fires, poetry publish --build pushes symphony_bdk_python-2.11.3 to PyPI.
  • Downstream bots pin symphony-bdk-python>=2.11.3 and verify pip install pulls cryptography 48.0.1.

Prepares a patch release so consumers can pull the cryptography>=48.0.1
constraint already merged to main via finos#390, closing CVE-2026-34180 on
downstream Symphony bots that depend on symphony-bdk-python.
@linux-foundation-easycla

linux-foundation-easyclaBot commented Aug 23, 2026

Copy link
Copy Markdown

CLA Signed
The committers listed above are authorized under a signed CLA.

  • ✅ login: matthewcummings / name: Matthew Cummings (e757da8)

@thibauult
thibauult merged commit 57aef93 into finos:mainAug 26, 2026
21 checks passed
matthewcummings added a commit to matthewcummings/symphony-bdk-python that referenced this pull request Aug 30, 2026
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. finos#397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
matthewcummings added a commit to matthewcummings/symphony-bdk-python that referenced this pull request Aug 30, 2026
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
matthewcummings added a commit that referenced this pull request Aug 31, 2026
* Raise cryptography ceiling to allow the patched 50.x
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. #397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
* Bump version to 2.11.4 to prepare a patch release
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in #390 sat unreleased for five days because the
version bump was a separate change (#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as #397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@matthewcummings@thibauult
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Bump version to 2.11.3 by matthewcummings · Pull Request #397 · finos/symphony-bdk-python · GitHub
Skip to content

Bump version to 2.11.3 - #397

Merged
thibauult merged 1 commit into
finos:mainfrom
matthewcummings:bump-version-to-2.11.3
Aug 26, 2026
Merged

Bump version to 2.11.3#397
thibauult merged 1 commit into
finos:mainfrom
matthewcummings:bump-version-to-2.11.3

Conversation

@matthewcummings

Copy link
Copy Markdown
Contributor

Summary

Bumps the version in pyproject.toml from 2.11.2 to 2.11.3 to prepare a patch release.

Context

The cryptography cap on the latest published release (v2.11.2) is ^46.0.0, which does not include the fix for CVE-2026-34180 (DoS via malformed ASN.1 input, patched in cryptography 48.0.1). Bots that depend on symphony-bdk-python cannot pin cryptography>=48.0.1 themselves because pip resolution fails against the transitive cap declared in BDK's own metadata.

The actual fix has already been merged to main via #390cryptography is now pinned to >=48.0.1,<49.0.0 and poetry.lock is regenerated accordingly. All that's missing to unblock downstream consumers is a published release cut from main.

This PR is just the version bump so that once merged, a maintainer can publish a GitHub Release tagged v2.11.3 and the existing release.yml workflow picks it up and pushes to PyPI.

Downstream impact

This unblocks CVE remediation on every downstream Symphony bot that depends on symphony-bdk-python — Symphony's InfoSec team is currently tracking the vulnerability across multiple bot deployments and the only unblock is a new release.

Test plan

  • Verified pyproject.toml version field is the only change.
  • After merge, a maintainer publishes a v2.11.3 GitHub Release from main.
  • release.yml fires, poetry publish --build pushes symphony_bdk_python-2.11.3 to PyPI.
  • Downstream bots pin symphony-bdk-python>=2.11.3 and verify pip install pulls cryptography 48.0.1.

Prepares a patch release so consumers can pull the cryptography>=48.0.1
constraint already merged to main via finos#390, closing CVE-2026-34180 on
downstream Symphony bots that depend on symphony-bdk-python.
@linux-foundation-easycla

linux-foundation-easyclaBot commented Aug 23, 2026

Copy link
Copy Markdown

CLA Signed
The committers listed above are authorized under a signed CLA.

  • ✅ login: matthewcummings / name: Matthew Cummings (e757da8)

@thibauult
thibauult merged commit 57aef93 into finos:mainAug 26, 2026
21 checks passed
matthewcummings added a commit to matthewcummings/symphony-bdk-python that referenced this pull request Aug 30, 2026
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. finos#397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
matthewcummings added a commit to matthewcummings/symphony-bdk-python that referenced this pull request Aug 30, 2026
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
matthewcummings added a commit that referenced this pull request Aug 31, 2026
* Raise cryptography ceiling to allow the patched 50.x
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. #397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
* Bump version to 2.11.4 to prepare a patch release
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in #390 sat unreleased for five days because the
version bump was a separate change (#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as #397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@matthewcummings@thibauult
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Bump version to 2.11.3 by matthewcummings · Pull Request #397 · finos/symphony-bdk-python · GitHub
Skip to content

Bump version to 2.11.3 - #397

Merged
thibauult merged 1 commit into
finos:mainfrom
matthewcummings:bump-version-to-2.11.3
Aug 26, 2026
Merged

Bump version to 2.11.3#397
thibauult merged 1 commit into
finos:mainfrom
matthewcummings:bump-version-to-2.11.3

Conversation

@matthewcummings

Copy link
Copy Markdown
Contributor

Summary

Bumps the version in pyproject.toml from 2.11.2 to 2.11.3 to prepare a patch release.

Context

The cryptography cap on the latest published release (v2.11.2) is ^46.0.0, which does not include the fix for CVE-2026-34180 (DoS via malformed ASN.1 input, patched in cryptography 48.0.1). Bots that depend on symphony-bdk-python cannot pin cryptography>=48.0.1 themselves because pip resolution fails against the transitive cap declared in BDK's own metadata.

The actual fix has already been merged to main via #390cryptography is now pinned to >=48.0.1,<49.0.0 and poetry.lock is regenerated accordingly. All that's missing to unblock downstream consumers is a published release cut from main.

This PR is just the version bump so that once merged, a maintainer can publish a GitHub Release tagged v2.11.3 and the existing release.yml workflow picks it up and pushes to PyPI.

Downstream impact

This unblocks CVE remediation on every downstream Symphony bot that depends on symphony-bdk-python — Symphony's InfoSec team is currently tracking the vulnerability across multiple bot deployments and the only unblock is a new release.

Test plan

  • Verified pyproject.toml version field is the only change.
  • After merge, a maintainer publishes a v2.11.3 GitHub Release from main.
  • release.yml fires, poetry publish --build pushes symphony_bdk_python-2.11.3 to PyPI.
  • Downstream bots pin symphony-bdk-python>=2.11.3 and verify pip install pulls cryptography 48.0.1.

Prepares a patch release so consumers can pull the cryptography>=48.0.1
constraint already merged to main via finos#390, closing CVE-2026-34180 on
downstream Symphony bots that depend on symphony-bdk-python.
@linux-foundation-easycla

linux-foundation-easyclaBot commented Aug 23, 2026

Copy link
Copy Markdown

CLA Signed
The committers listed above are authorized under a signed CLA.

  • ✅ login: matthewcummings / name: Matthew Cummings (e757da8)

@thibauult
thibauult merged commit 57aef93 into finos:mainAug 26, 2026
21 checks passed
matthewcummings added a commit to matthewcummings/symphony-bdk-python that referenced this pull request Aug 30, 2026
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. finos#397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
matthewcummings added a commit to matthewcummings/symphony-bdk-python that referenced this pull request Aug 30, 2026
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
matthewcummings added a commit that referenced this pull request Aug 31, 2026
* Raise cryptography ceiling to allow the patched 50.x
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. #397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
* Bump version to 2.11.4 to prepare a patch release
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in #390 sat unreleased for five days because the
version bump was a separate change (#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as #397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@matthewcummings@thibauult
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Bump version to 2.11.3 by matthewcummings · Pull Request #397 · finos/symphony-bdk-python · GitHub
Skip to content

Bump version to 2.11.3 - #397

Merged
thibauult merged 1 commit into
finos:mainfrom
matthewcummings:bump-version-to-2.11.3
Aug 26, 2026
Merged

Bump version to 2.11.3#397
thibauult merged 1 commit into
finos:mainfrom
matthewcummings:bump-version-to-2.11.3

Conversation

@matthewcummings

Copy link
Copy Markdown
Contributor

Summary

Bumps the version in pyproject.toml from 2.11.2 to 2.11.3 to prepare a patch release.

Context

The cryptography cap on the latest published release (v2.11.2) is ^46.0.0, which does not include the fix for CVE-2026-34180 (DoS via malformed ASN.1 input, patched in cryptography 48.0.1). Bots that depend on symphony-bdk-python cannot pin cryptography>=48.0.1 themselves because pip resolution fails against the transitive cap declared in BDK's own metadata.

The actual fix has already been merged to main via #390cryptography is now pinned to >=48.0.1,<49.0.0 and poetry.lock is regenerated accordingly. All that's missing to unblock downstream consumers is a published release cut from main.

This PR is just the version bump so that once merged, a maintainer can publish a GitHub Release tagged v2.11.3 and the existing release.yml workflow picks it up and pushes to PyPI.

Downstream impact

This unblocks CVE remediation on every downstream Symphony bot that depends on symphony-bdk-python — Symphony's InfoSec team is currently tracking the vulnerability across multiple bot deployments and the only unblock is a new release.

Test plan

  • Verified pyproject.toml version field is the only change.
  • After merge, a maintainer publishes a v2.11.3 GitHub Release from main.
  • release.yml fires, poetry publish --build pushes symphony_bdk_python-2.11.3 to PyPI.
  • Downstream bots pin symphony-bdk-python>=2.11.3 and verify pip install pulls cryptography 48.0.1.

Prepares a patch release so consumers can pull the cryptography>=48.0.1
constraint already merged to main via finos#390, closing CVE-2026-34180 on
downstream Symphony bots that depend on symphony-bdk-python.
@linux-foundation-easycla

linux-foundation-easyclaBot commented Aug 23, 2026

Copy link
Copy Markdown

CLA Signed
The committers listed above are authorized under a signed CLA.

  • ✅ login: matthewcummings / name: Matthew Cummings (e757da8)

@thibauult
thibauult merged commit 57aef93 into finos:mainAug 26, 2026
21 checks passed
matthewcummings added a commit to matthewcummings/symphony-bdk-python that referenced this pull request Aug 30, 2026
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. finos#397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
matthewcummings added a commit to matthewcummings/symphony-bdk-python that referenced this pull request Aug 30, 2026
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
matthewcummings added a commit that referenced this pull request Aug 31, 2026
* Raise cryptography ceiling to allow the patched 50.x
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. #397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
* Bump version to 2.11.4 to prepare a patch release
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in #390 sat unreleased for five days because the
version bump was a separate change (#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as #397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@matthewcummings@thibauult
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); Bump version to 2.11.3 by matthewcummings · Pull Request #397 · finos/symphony-bdk-python · GitHub
Skip to content

Bump version to 2.11.3 - #397

Merged
thibauult merged 1 commit into
finos:mainfrom
matthewcummings:bump-version-to-2.11.3
Aug 26, 2026
Merged

Bump version to 2.11.3#397
thibauult merged 1 commit into
finos:mainfrom
matthewcummings:bump-version-to-2.11.3

Conversation

@matthewcummings

Copy link
Copy Markdown
Contributor

Summary

Bumps the version in pyproject.toml from 2.11.2 to 2.11.3 to prepare a patch release.

Context

The cryptography cap on the latest published release (v2.11.2) is ^46.0.0, which does not include the fix for CVE-2026-34180 (DoS via malformed ASN.1 input, patched in cryptography 48.0.1). Bots that depend on symphony-bdk-python cannot pin cryptography>=48.0.1 themselves because pip resolution fails against the transitive cap declared in BDK's own metadata.

The actual fix has already been merged to main via #390cryptography is now pinned to >=48.0.1,<49.0.0 and poetry.lock is regenerated accordingly. All that's missing to unblock downstream consumers is a published release cut from main.

This PR is just the version bump so that once merged, a maintainer can publish a GitHub Release tagged v2.11.3 and the existing release.yml workflow picks it up and pushes to PyPI.

Downstream impact

This unblocks CVE remediation on every downstream Symphony bot that depends on symphony-bdk-python — Symphony's InfoSec team is currently tracking the vulnerability across multiple bot deployments and the only unblock is a new release.

Test plan

  • Verified pyproject.toml version field is the only change.
  • After merge, a maintainer publishes a v2.11.3 GitHub Release from main.
  • release.yml fires, poetry publish --build pushes symphony_bdk_python-2.11.3 to PyPI.
  • Downstream bots pin symphony-bdk-python>=2.11.3 and verify pip install pulls cryptography 48.0.1.

Prepares a patch release so consumers can pull the cryptography>=48.0.1
constraint already merged to main via finos#390, closing CVE-2026-34180 on
downstream Symphony bots that depend on symphony-bdk-python.
@linux-foundation-easycla

linux-foundation-easyclaBot commented Aug 23, 2026

Copy link
Copy Markdown

CLA Signed
The committers listed above are authorized under a signed CLA.

  • ✅ login: matthewcummings / name: Matthew Cummings (e757da8)

@thibauult
thibauult merged commit 57aef93 into finos:mainAug 26, 2026
21 checks passed
matthewcummings added a commit to matthewcummings/symphony-bdk-python that referenced this pull request Aug 30, 2026
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. finos#397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
matthewcummings added a commit to matthewcummings/symphony-bdk-python that referenced this pull request Aug 30, 2026
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
matthewcummings added a commit that referenced this pull request Aug 31, 2026
* Raise cryptography ceiling to allow the patched 50.x
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. #397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
* Bump version to 2.11.4 to prepare a patch release
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in #390 sat unreleased for five days because the
version bump was a separate change (#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as #397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@matthewcummings@thibauult