Skip to content

chore(deps): update cryptography requirement from <50.0.0,>=46.0.3 to >=46.0.3,<51.0.0 - #2646

Merged
jonahgabriel merged 6 commits into
devfrom
dependabot/pip/cryptography-gte-46.0.3-and-lt-51.0.0
Aug 5, 2026
Merged

jonahgabriel merged 6 commits into
devfrom
dependabot/pip/cryptography-gte-46.0.3-and-lt-51.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 4, 2026 •

Copy link
Copy Markdown
Contributor

Updates the requirements on cryptography to permit the latest version.

Changelog

Sourced from cryptography's changelog.

50.0.0 - 2026-07-31


* **SECURITY ISSUE**:
  :func:`~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der`
  and its PEM and S/MIME variants no longer expose distinguishable errors or
  timing when unwrapping a ``RecipientInfo``'s ``encryptedKey``, which could
  act as a Bleichenbacher oracle for callers that decrypt untrusted messages.
  A random key is now substituted on failure, as described in :rfc:`3218`.
  Credit to **@X1AOxiang** for reporting the issue. **CVE-2026-69247**
* Deprecated Diffie-Hellman key exchange over finite fields (FFDH).
  Everything FFDH is deprecated, including the types in
  ``cryptography.hazmat.primitives.asymmetric.dh`` and loading FFDH keys or
  parameters with the key loading APIs. Users should migrate to a more
  modern key exchange algorithm.
* Added ``xof()`` class methods to
  :class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and
  :class:`~cryptography.hazmat.primitives.hashes.SHAKE256` for constructing
  algorithm instances configured for use with
  :class:`~cryptography.hazmat.primitives.hashes.XOFHash`.
* The :mod:`X.509 verification <cryptography.x509.verification>` APIs are now
  considered stable and are subject to our API stability policy.
* Added the :doc:`/cobblestone` recipe, an implementation of the
  Cobblestone-128 and Cobblestone-256 instantiations of the `C2SP
  chunked-encryption specification
  <https://c2sp.org/chunked-encryption>`_ for streaming authenticated
  encryption of large messages.
* Parsing a Signed Certificate Timestamp list now rejects encodings that
  carry trailing bytes after the list or after an individual SCT, instead of
  silently ignoring them.
* Added support for using :class:`~cryptography.x509.Name` as a field type in
  the :doc:`/hazmat/asn1/index` module.
* Loading a public key or an EC private key now rejects DER where the
  ``subjectPublicKey`` (or EC ``publicKey``) ``BIT STRING`` declares a non-zero
  number of unused bits, instead of silently ignoring it.
* Parsing a CRL entry's ``InvalidityDate`` extension now rejects a
  ``GeneralizedTime`` that carries fractional seconds or another non-DER form,
  matching the strict encoding already required for every other X.509 time
  field.
* :func:`~cryptography.x509.ocsp.load_der_ocsp_request` and
  :func:`~cryptography.x509.ocsp.load_der_ocsp_response` now reject a request
  or response whose ``version`` field is not ``v1``, the only version defined
  by RFC 6960, matching the version validation already performed when loading
  certificates, CSRs and CRLs.
* :class:`~cryptography.hazmat.primitives.hashes.XOFHash` is now supported
  when building against AWS-LC.
* HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when
  building against AWS-LC.
* Diffie-Hellman (:doc:`/hazmat/primitives/asymmetric/dh`) is now supported
  when building against AWS-LC.
</tr></table> 

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Aug 4, 2026
@github-actions

github-actions Bot commented Aug 4, 2026 •

Copy link
Copy Markdown
Contributor

✅ Hostile Reviewer — PASSED

Blocking findings (critical): 0
Total findings: 0
Models succeeded: qwen3-review,qwen3-review-b


Gate semantics (pilot phase)

Verdict Meaning Blocks merge?
passed No critical findings No
blocked CRITICAL findings found Yes
degraded All models unavailable (infra) No (pilot)

Powered by omniintelligence.review_pairing.cli_review — node-based adversarial review via HandlerLlmCliSubprocess (OMN-8468/OMN-8524)

Updates the requirements on [cryptography](https://github.com/pyca/cryptography) to permit the latest version.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@46.0.3...50.0.0)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 50.0.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/cryptography-gte-46.0.3-and-lt-51.0.0 branch from 260328a to 47d3dbc Compare August 4, 2026 15:52
@jonahgabriel

Copy link
Copy Markdown
Collaborator

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Aug 4, 2026

Copy link
Copy Markdown
Contributor Author

Looks like this PR is already up-to-date with dev! If you'd still like to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

@jonahgabriel
jonahgabriel merged commit d1c5927 into dev Aug 5, 2026
164 of 169 checks passed
@jonahgabriel
jonahgabriel deleted the dependabot/pip/cryptography-gte-46.0.3-and-lt-51.0.0 branch August 5, 2026 21:48
jonahgabriel added a commit that referenced this pull request Aug 8, 2026
…TERNAL_CONTEXTS

OMN-13873 shipped `Dep Provenance Gate` (dep-provenance-gate.yml) but its own
DoD item "required on infra dev/main branch protection" was never fulfilled
live: the context reports on every PR (no job-level `if:`) but blocks
nothing on dev or main today.

Measured per ci_summary_gate.py's own admission rule: 16/16 present, 16/16
green over the last 16 merged omnibase_infra dev PRs (#2646-#2669,
2026-08-04T16:56Z -> 2026-08-07T01:08Z, started_at <= mergedAt). Re-verified
against the SAME #2546-#2567 golden-fixture window already pinned by
test_ci_summary_gate.py: also 16/16 present, 16/16 green. Both windows agree,
so the context is folded into EXPECTED_EXTERNAL_CONTEXTS and the existing
fixture rows, closing it fail-closed on dev via the sole required `CI
Summary` umbrella (code path per CLAUDE.md rule 10 — no branch-protection
API mutation in this PR).

Also bundles a pre-existing, unrelated node-migration vendor-sync drift fix
(scripts/sync-node-migrations.sh output) that was already red on dev HEAD
before this change and blocked the pre-commit gate for this PR
(no-pre-existing-excuse policy).
jonahgabriel added a commit that referenced this pull request Aug 21, 2026
…TERNAL_CONTEXTS (#2684)

* fix(OMN-15737): admit Dep Provenance Gate into CI Summary EXPECTED_EXTERNAL_CONTEXTS

OMN-13873 shipped `Dep Provenance Gate` (dep-provenance-gate.yml) but its own
DoD item "required on infra dev/main branch protection" was never fulfilled
live: the context reports on every PR (no job-level `if:`) but blocks
nothing on dev or main today.

Measured per ci_summary_gate.py's own admission rule: 16/16 present, 16/16
green over the last 16 merged omnibase_infra dev PRs (#2646-#2669,
2026-08-04T16:56Z -> 2026-08-07T01:08Z, started_at <= mergedAt). Re-verified
against the SAME #2546-#2567 golden-fixture window already pinned by
test_ci_summary_gate.py: also 16/16 present, 16/16 green. Both windows agree,
so the context is folded into EXPECTED_EXTERNAL_CONTEXTS and the existing
fixture rows, closing it fail-closed on dev via the sole required `CI
Summary` umbrella (code path per CLAUDE.md rule 10 — no branch-protection
API mutation in this PR).

Also bundles a pre-existing, unrelated node-migration vendor-sync drift fix
(scripts/sync-node-migrations.sh output) that was already red on dev HEAD
before this change and blocked the pre-commit gate for this PR
(no-pre-existing-excuse policy).

* fix(OMN-15737): preserve original 1-space indent in fixture json

The previous commit's json.dump reformatted the whole fixture file (2-space
indent vs the file's original 1-space convention), producing an 8000-line
diff noise. Re-dump with indent=1 to match the existing style; diff is now
scoped to the actual added rows.

* fix(OMN-15737): declare the 2 newly-vendored node migrations in the manifest

test_application_migration_manifest.py caught what the bundled vendor-sync
fix (previous commit) missed: adding node_canary_score_reducer/0003 and
node_projection_registration/0004 to the vendor tree without a matching
declaration in docker/migrations/forward/_ledger/application-migrations.tsv
left the manifest incomplete (94 declared vs 96 on disk).

Domain classification follows the established, already-committed pattern
for each node rather than inventing new policy:
- node_canary_score_reducer/0003 (capability_scores tenant_id TEXT->UUID):
  domain=tenant, continuing sibling 0002's tenant domain for the same
  already-tenant-classified column.
- node_projection_registration/0004 (node_service_registry NO FORCE RLS):
  domain=omninode_internal, matching the file's own inline OMN-15336
  item-4 domain corroboration (contract.yaml db_io.schema=omninode_internal,
  2026-08-02 operator ruling, OMN-15656 grants-derivation correction).

Full impacted suite (scripts/ci/tests, scripts/tests, tests/ci, tests/scripts,
tests/unit/scripts) re-run green: 3011 passed, 5 skipped.

* fix(OMN-15737): dedupe stale vendor-migration TSV rows introduced by dev rebase

The OMN-15732 deadlock-fix rebase auto-merged two intermediate commits'
TSV additions for node_canary_score_reducer/0003 and
node_projection_registration/0004 with stale checksums, alongside dev's
already-correct rows for the same files (dev holds the adjudicated
single-file 0003 since 211e81e). Take dev's TSV wholesale -- this PR
has no legitimate TSV diff of its own.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant