Repository navigation
chore(deps): update cryptography requirement from <50.0.0,>=46.0.3 to >=46.0.3,<51.0.0 - #2646
Merged
jonahgabriel merged 6 commits intoAug 5, 2026
Conversation
Contributor
✅ Hostile Reviewer — PASSEDBlocking findings (critical): 0 Gate semantics (pilot phase)
Powered by omniintelligence.review_pairing.cli_review — node-based adversarial review via HandlerLlmCliSubprocess (OMN-8468/OMN-8524) |
Updates the requirements on [cryptography](https://github.com/pyca/cryptography) to permit the latest version. - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@46.0.3...50.0.0) --- updated-dependencies: - dependency-name: cryptography dependency-version: 50.0.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/pip/cryptography-gte-46.0.3-and-lt-51.0.0
branch
from
August 4, 2026 15:52
260328a to
47d3dbc
Compare
Collaborator
|
@dependabot rebase |
Contributor
Author
|
Looks like this PR is already up-to-date with dev! If you'd still like to recreate it from scratch, overwriting any edits, you can request |
…raphy-gte-46.0.3-and-lt-51.0.0
jonahgabriel
deleted the
dependabot/pip/cryptography-gte-46.0.3-and-lt-51.0.0
branch
August 5, 2026 21:48
jonahgabriel
added a commit
that referenced
this pull request
Aug 8, 2026
…TERNAL_CONTEXTS OMN-13873 shipped `Dep Provenance Gate` (dep-provenance-gate.yml) but its own DoD item "required on infra dev/main branch protection" was never fulfilled live: the context reports on every PR (no job-level `if:`) but blocks nothing on dev or main today. Measured per ci_summary_gate.py's own admission rule: 16/16 present, 16/16 green over the last 16 merged omnibase_infra dev PRs (#2646-#2669, 2026-08-04T16:56Z -> 2026-08-07T01:08Z, started_at <= mergedAt). Re-verified against the SAME #2546-#2567 golden-fixture window already pinned by test_ci_summary_gate.py: also 16/16 present, 16/16 green. Both windows agree, so the context is folded into EXPECTED_EXTERNAL_CONTEXTS and the existing fixture rows, closing it fail-closed on dev via the sole required `CI Summary` umbrella (code path per CLAUDE.md rule 10 — no branch-protection API mutation in this PR). Also bundles a pre-existing, unrelated node-migration vendor-sync drift fix (scripts/sync-node-migrations.sh output) that was already red on dev HEAD before this change and blocked the pre-commit gate for this PR (no-pre-existing-excuse policy).
jonahgabriel
added a commit
that referenced
this pull request
Aug 21, 2026
…TERNAL_CONTEXTS (#2684) * fix(OMN-15737): admit Dep Provenance Gate into CI Summary EXPECTED_EXTERNAL_CONTEXTS OMN-13873 shipped `Dep Provenance Gate` (dep-provenance-gate.yml) but its own DoD item "required on infra dev/main branch protection" was never fulfilled live: the context reports on every PR (no job-level `if:`) but blocks nothing on dev or main today. Measured per ci_summary_gate.py's own admission rule: 16/16 present, 16/16 green over the last 16 merged omnibase_infra dev PRs (#2646-#2669, 2026-08-04T16:56Z -> 2026-08-07T01:08Z, started_at <= mergedAt). Re-verified against the SAME #2546-#2567 golden-fixture window already pinned by test_ci_summary_gate.py: also 16/16 present, 16/16 green. Both windows agree, so the context is folded into EXPECTED_EXTERNAL_CONTEXTS and the existing fixture rows, closing it fail-closed on dev via the sole required `CI Summary` umbrella (code path per CLAUDE.md rule 10 — no branch-protection API mutation in this PR). Also bundles a pre-existing, unrelated node-migration vendor-sync drift fix (scripts/sync-node-migrations.sh output) that was already red on dev HEAD before this change and blocked the pre-commit gate for this PR (no-pre-existing-excuse policy). * fix(OMN-15737): preserve original 1-space indent in fixture json The previous commit's json.dump reformatted the whole fixture file (2-space indent vs the file's original 1-space convention), producing an 8000-line diff noise. Re-dump with indent=1 to match the existing style; diff is now scoped to the actual added rows. * fix(OMN-15737): declare the 2 newly-vendored node migrations in the manifest test_application_migration_manifest.py caught what the bundled vendor-sync fix (previous commit) missed: adding node_canary_score_reducer/0003 and node_projection_registration/0004 to the vendor tree without a matching declaration in docker/migrations/forward/_ledger/application-migrations.tsv left the manifest incomplete (94 declared vs 96 on disk). Domain classification follows the established, already-committed pattern for each node rather than inventing new policy: - node_canary_score_reducer/0003 (capability_scores tenant_id TEXT->UUID): domain=tenant, continuing sibling 0002's tenant domain for the same already-tenant-classified column. - node_projection_registration/0004 (node_service_registry NO FORCE RLS): domain=omninode_internal, matching the file's own inline OMN-15336 item-4 domain corroboration (contract.yaml db_io.schema=omninode_internal, 2026-08-02 operator ruling, OMN-15656 grants-derivation correction). Full impacted suite (scripts/ci/tests, scripts/tests, tests/ci, tests/scripts, tests/unit/scripts) re-run green: 3011 passed, 5 skipped. * fix(OMN-15737): dedupe stale vendor-migration TSV rows introduced by dev rebase The OMN-15732 deadlock-fix rebase auto-merged two intermediate commits' TSV additions for node_canary_score_reducer/0003 and node_projection_registration/0004 with stale checksums, alongside dev's already-correct rows for the same files (dev holds the adjudicated single-file 0003 since 211e81e). Take dev's TSV wholesale -- this PR has no legitimate TSV diff of its own.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates the requirements on cryptography to permit the latest version.
Changelog
Sourced from cryptography's changelog.
... (truncated)
Commits
dcb7050Prepare for 50.0.0 release (#15372)53fccd9Don't leak how PKCS#7 encryptedKey decryption failed (#15369)d472f97Addfrom __future__ import annotationsto all src/ Python files (#15371)908773dBump downstream dependencies in CI (#15368)2cc07ccBump BoringSSL, OpenSSL, AWS-LC in CI (#15367)c94ede9chore(deps): bump ruff from 0.16.0 to 0.16.1 (#15366)67a8308chore(deps): bump virtualenv from 21.7.0 to 21.7.1 (#15365)95018ffRelease the GIL in one-shot AEAD encrypt/decrypt (#15361)6954733Release the GIL during DH and DSA parameter generation (#15364)6893b94Import _serialization instead of serialization in x509/extensions (#15363)