Skip to content

chore(deps): bump the production-dependencies group across 1 directory with 2 updates - #8

Merged
Jeshua Ben Joseph (Theaxiom) merged 1 commit into
mainfrom
dependabot/pip/production-dependencies-c33df8cba3
Sep 28, 2026
Merged

Jeshua Ben Joseph (Theaxiom) merged 1 commit into
mainfrom
dependabot/pip/production-dependencies-c33df8cba3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 11, 2026 •

Copy link
Copy Markdown
Contributor

Updates the requirements on pydantic and cryptography to permit the latest version.
Updates pydantic to 2.13.5

Release notes

Sourced from pydantic's releases.

v2.13.5 (2026-08-28)

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731
Changelog

Sourced from pydantic's changelog.

v2.13.5 (2026-08-28)

GitHub release

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731

v2.13.4 (2026-05-06)

GitHub release

What's Changed

Packaging

Fixes

v2.13.3 (2026-04-20)

GitHub release

What's Changed

Fixes

v2.13.2 (2026-04-17)

GitHub release

What's Changed

Fixes

  • Fix ValidationInfo.field_name missing with model_validate_json() by @​Viicos in #13084

v2.13.1 (2026-04-15)

... (truncated)

Commits
  • 001dea0 Bump pypa/gh-action-pypi-publish action to v1.14.2
  • 558379f Bump twine to v7.0.0
  • 2cfd5d3 Do not check for docs build
  • a735bee Fix more Clippy lints
  • 7eed4a1 Fix Clippy 0.1.95 warnings
  • b353bbb Prepare release v2.13.5
  • 63d2ccc Count validated model fields once in smart unions
  • a53ec2e Speed up PyPy CI tests
  • d65e0f9 Workaround circular import error in Mypy
  • 47a6dbf Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer
  • Additional commits viewable in compare view

Updates cryptography to 50.0.1

Changelog

Sourced from cryptography's changelog.

50.0.1 - 2026-08-25


* Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.2.

.. _v50-0-0:

50.0.0 - 2026-07-31

  • SECURITY ISSUE: :func:~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der and its PEM and S/MIME variants no longer expose distinguishable errors or timing when unwrapping a RecipientInfo's encryptedKey, which could act as a Bleichenbacher oracle for callers that decrypt untrusted messages. A random key is now substituted on failure, as described in :rfc:3218. Credit to @​X1AOxiang for reporting the issue. CVE-2026-69247
  • Deprecated Diffie-Hellman key exchange over finite fields (FFDH). Everything FFDH is deprecated, including the types in cryptography.hazmat.primitives.asymmetric.dh and loading FFDH keys or parameters with the key loading APIs. Users should migrate to a more modern key exchange algorithm.
  • Added xof() class methods to :class:~cryptography.hazmat.primitives.hashes.SHAKE128 and :class:~cryptography.hazmat.primitives.hashes.SHAKE256 for constructing algorithm instances configured for use with :class:~cryptography.hazmat.primitives.hashes.XOFHash.
  • The :mod:X.509 verification <cryptography.x509.verification> APIs are now considered stable and are subject to our API stability policy.
  • Added the :doc:/cobblestone recipe, an implementation of the Cobblestone-128 and Cobblestone-256 instantiations of the C2SP chunked-encryption specification <https://c2sp.org/chunked-encryption>_ for streaming authenticated encryption of large messages.
  • Parsing a Signed Certificate Timestamp list now rejects encodings that carry trailing bytes after the list or after an individual SCT, instead of silently ignoring them.
  • Added support for using :class:~cryptography.x509.Name as a field type in the :doc:/hazmat/asn1/index module.
  • Loading a public key or an EC private key now rejects DER where the subjectPublicKey (or EC publicKey) BIT STRING declares a non-zero number of unused bits, instead of silently ignoring it.
  • Parsing a CRL entry's InvalidityDate extension now rejects a GeneralizedTime that carries fractional seconds or another non-DER form, matching the strict encoding already required for every other X.509 time field.
  • :func:~cryptography.x509.ocsp.load_der_ocsp_request and :func:~cryptography.x509.ocsp.load_der_ocsp_response now reject a request or response whose version field is not v1, the only version defined by RFC 6960, matching the version validation already performed when loading

... (truncated)

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot @github

dependabot Bot commented on behalf of github May 11, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, python. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@Theaxiom

Copy link
Copy Markdown
Member

Held for the maintainer: this raises runtime dependency floors of a published library. pydantic>=2.13.4 closes no advisory. cryptography>=48.0.0 is a major floor raise and would still permit GHSA-g6cj-pr64-35w5, GHSA-jwv3-5hgf-82ww and GHSA-m2h6-j472-rp4c (fixed in 49.0.0/50.0.0); the floor that closes all four open cryptography advisories (with GHSA-537c-gmf6-5ccf) is >=50.0.0. The suite (176 tests, 41 of them over the Ed25519 SEAL path) passes at cryptography 47.0.0, 50.0.0 and 50.0.1. Waits on a ruling on the cryptography floor.

Jeshua Ben Joseph (Theaxiom) added a commit that referenced this pull request Sep 28, 2026
The runtime range cryptography>=47.0.0 admitted four advisories
(GitHub advisory database, gh api /advisories/<id>):
  GHSA-537c-gmf6-5ccf  high    vulnerable OpenSSL in wheels, < 48.0.1
  GHSA-g6cj-pr64-35w5  high    PKCS#7 EnvelopedData Bleichenbacher oracle,
                               CVE-2026-69247, >= 44.0.0 < 50.0.0
  GHSA-jwv3-5hgf-82ww  high    exponential X.509 path building,
                               CVE-2026-69249, >= 42.0.0 < 49.0.0
  GHSA-m2h6-j472-rp4c  medium  wildcard DNS name escapes permittedSubtrees,
                               CVE-2026-69248, >= 45.0.0 < 49.0.0
Floor moved: dependencies cryptography>=47.0.0 -> cryptography>=50.0.0,
the lowest release that closes all four. A three-major floor raise of a
runtime dependency of a published SDK, landed on the coordinator's
delegated ruling of 2026-09-28 (the advisory rule over the major rule).
It reaches consumers only when a release is cut; the version string
0.15.0a0 is unchanged. Supersedes the cryptography half of Dependabot
#8 (>=48.0.0, which would still admit three of the four).

Evidence, ci.yml's steps under Python 3.11.16:
  at cryptography==50.0.0 (the floor) and at 50.0.1 (resolved latest):
    black --check aegis   rc=0
    ruff check aegis      "All checks passed!"
    mypy aegis            "Success: no issues found in 11 source files"
    python -m build       "Successfully built aegis_sdk-0.15.0a0.tar.gz and aegis_sdk-0.15.0a0-py3-none-any.whl"
    pytest                "176 passed, 1 warning" (41 in tests/test_seal.py
                          drive the Ed25519 path the SDK uses cryptography for)
  pip-audit 2.10.1 -s osv .                        "No known vulnerabilities found"
  pip-audit -s osv on the floor set (cryptography 50.0.0, pydantic 2.13.3,
    httpx 0.28.1, pyyaml 6.0.3)                    "No known vulnerabilities found"
    (was 4 advisories at cryptography 47.0.0)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E97JPo4pWhtPuJZqZVDfGk
Signed-off-by: Jeshua ben Joseph <jeshua@100monkeys.ai>
@Theaxiom

Copy link
Copy Markdown
Member

Update: the cryptography half of this PR is superseded by 07ad7db on main, which raises the floor to cryptography>=50.0.0 (closes GHSA-537c-gmf6-5ccf, GHSA-g6cj-pr64-35w5, GHSA-jwv3-5hgf-82ww, GHSA-m2h6-j472-rp4c; >=48.0.0 would have left three open). CI 36374988999 and Security Audit 36374989081 green. The pydantic>=2.13.4 half stays held: it closes no advisory.

…y with 2 updates

Updates the requirements on [pydantic](https://github.com/pydantic/pydantic) and [cryptography](https://github.com/pyca/cryptography) to permit the latest version.

Updates `pydantic` to 2.13.5
- [Release notes](https://github.com/pydantic/pydantic/releases)
- [Changelog](https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md)
- [Commits](pydantic/pydantic@v2.13.3...v2.13.5)

Updates `cryptography` to 50.0.1
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@50.0.0...50.0.1)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 48.0.0
  dependency-type: direct:production
  dependency-group: production-dependencies
- dependency-name: pydantic
  dependency-version: 2.13.4
  dependency-type: direct:production
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump the production-dependencies group with 2 updates chore(deps): bump the production-dependencies group across 1 directory with 2 updates Sep 28, 2026
@dependabot
dependabot Bot force-pushed the dependabot/pip/production-dependencies-c33df8cba3 branch from cf993ae to 36c0db7 Compare September 28, 2026 10:08
@Theaxiom
Jeshua Ben Joseph (Theaxiom) merged commit 1b7452f into main Sep 28, 2026
5 checks passed
@dependabot
dependabot Bot deleted the dependabot/pip/production-dependencies-c33df8cba3 branch September 28, 2026 18:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant