chore(deps): bump the production-dependencies group across 1 directory with 2 updates - #8
Conversation
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
Held for the maintainer: this raises runtime dependency floors of a published library. pydantic>=2.13.4 closes no advisory. cryptography>=48.0.0 is a major floor raise and would still permit GHSA-g6cj-pr64-35w5, GHSA-jwv3-5hgf-82ww and GHSA-m2h6-j472-rp4c (fixed in 49.0.0/50.0.0); the floor that closes all four open cryptography advisories (with GHSA-537c-gmf6-5ccf) is >=50.0.0. The suite (176 tests, 41 of them over the Ed25519 SEAL path) passes at cryptography 47.0.0, 50.0.0 and 50.0.1. Waits on a ruling on the cryptography floor. |
The runtime range cryptography>=47.0.0 admitted four advisories (GitHub advisory database, gh api /advisories/<id>): GHSA-537c-gmf6-5ccf high vulnerable OpenSSL in wheels, < 48.0.1 GHSA-g6cj-pr64-35w5 high PKCS#7 EnvelopedData Bleichenbacher oracle, CVE-2026-69247, >= 44.0.0 < 50.0.0 GHSA-jwv3-5hgf-82ww high exponential X.509 path building, CVE-2026-69249, >= 42.0.0 < 49.0.0 GHSA-m2h6-j472-rp4c medium wildcard DNS name escapes permittedSubtrees, CVE-2026-69248, >= 45.0.0 < 49.0.0 Floor moved: dependencies cryptography>=47.0.0 -> cryptography>=50.0.0, the lowest release that closes all four. A three-major floor raise of a runtime dependency of a published SDK, landed on the coordinator's delegated ruling of 2026-09-28 (the advisory rule over the major rule). It reaches consumers only when a release is cut; the version string 0.15.0a0 is unchanged. Supersedes the cryptography half of Dependabot #8 (>=48.0.0, which would still admit three of the four). Evidence, ci.yml's steps under Python 3.11.16: at cryptography==50.0.0 (the floor) and at 50.0.1 (resolved latest): black --check aegis rc=0 ruff check aegis "All checks passed!" mypy aegis "Success: no issues found in 11 source files" python -m build "Successfully built aegis_sdk-0.15.0a0.tar.gz and aegis_sdk-0.15.0a0-py3-none-any.whl" pytest "176 passed, 1 warning" (41 in tests/test_seal.py drive the Ed25519 path the SDK uses cryptography for) pip-audit 2.10.1 -s osv . "No known vulnerabilities found" pip-audit -s osv on the floor set (cryptography 50.0.0, pydantic 2.13.3, httpx 0.28.1, pyyaml 6.0.3) "No known vulnerabilities found" (was 4 advisories at cryptography 47.0.0) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E97JPo4pWhtPuJZqZVDfGk Signed-off-by: Jeshua ben Joseph <jeshua@100monkeys.ai>
|
Update: the cryptography half of this PR is superseded by 07ad7db on main, which raises the floor to cryptography>=50.0.0 (closes GHSA-537c-gmf6-5ccf, GHSA-g6cj-pr64-35w5, GHSA-jwv3-5hgf-82ww, GHSA-m2h6-j472-rp4c; >=48.0.0 would have left three open). CI 36374988999 and Security Audit 36374989081 green. The pydantic>=2.13.4 half stays held: it closes no advisory. |
…y with 2 updates Updates the requirements on [pydantic](https://github.com/pydantic/pydantic) and [cryptography](https://github.com/pyca/cryptography) to permit the latest version. Updates `pydantic` to 2.13.5 - [Release notes](https://github.com/pydantic/pydantic/releases) - [Changelog](https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md) - [Commits](pydantic/pydantic@v2.13.3...v2.13.5) Updates `cryptography` to 50.0.1 - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@50.0.0...50.0.1) --- updated-dependencies: - dependency-name: cryptography dependency-version: 48.0.0 dependency-type: direct:production dependency-group: production-dependencies - dependency-name: pydantic dependency-version: 2.13.4 dependency-type: direct:production dependency-group: production-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
cf993ae to
36c0db7
Compare
Updates the requirements on pydantic and cryptography to permit the latest version.
Updates
pydanticto 2.13.5Release notes
Sourced from pydantic's releases.
Changelog
Sourced from pydantic's changelog.
... (truncated)
Commits
001dea0Bumppypa/gh-action-pypi-publishaction to v1.14.2558379fBump twine to v7.0.02cfd5d3Do not check for docs builda735beeFix more Clippy lints7eed4a1Fix Clippy 0.1.95 warningsb353bbbPrepare release v2.13.563d2cccCount validated model fields once in smart unionsa53ec2eSpeed up PyPy CI testsd65e0f9Workaround circular import error in Mypy47a6dbfFix missing GC traversal inpydantic-coreforGeneralFieldsSerializerUpdates
cryptographyto 50.0.1Changelog
Sourced from cryptography's changelog.
... (truncated)
Commits
ffde75abump for 50.0.1 + changelog (#15520)