← Back to issue list

deps: update cryptography to v39.0

View original Github issue

Metadata

Project
charmcraft
Number
#1024
Type
pull request
State
merged
Author
lengau
Labels
Created
Updated
Closed

Current evaluation

Merged after updating cryptography to v39.0 to address security vulnerabilities and updating snapcraft.yaml for rust dependencies. Delayed until spread tests passed on ppc64el and s390x. Resolves #991.

Suggested action:

No scores available.

Issue body

Since older versions of cryptography now have known security issues, it's more necessary to update. This not only makes that change but also updates the snapcraft.yaml to include the appropriate rust dependencies. Should fix #991

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Merged after updating cryptography to v39.0 to address security vulnerabilities and updating snapcraft.yaml for rust dependencies. Delayed until spread tests passed on ppc64el and s390x. Resolves #991.
qwen3.6-35b-a3b-mtp-q6 Merged update to cryptography v39.0 to address security vulnerabilities. Updated snapcraft.yaml for rust dependencies and verified cross-architecture builds. Resolves #991.
qwen3.6-35b-a3b-mtp-q6 Merged cryptography v39.0 update to address security vulnerabilities, plus snapcraft.yaml rust dependency changes. Verified across armhf, ppc64el, and s390x before merging, resolving issue #991.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#4136 deps: update cryptography dependency snapcraft merged Merged into main after approval and passing CI checks. Updates the cryptography dependency without changing code coverage.
75%
#2640 build(deps): bump cryptography from 45.0.4 to 46.0.6 in /tests/spread/ubuntu-26.04/test-cmd charmcraft closed Closed after maintainer @lengau ran @dependabot recreate. The bot deferred updates to a future release. CI failures on snap tests and typechecking blocked merging. Dependabot closed the PR to await a newer version.
75%
#4195 build(deps): bump cryptography from 40.0.2 to 41.0.0 snapcraft merged Dependabot dependency update to bump cryptography from 40.0.2 to 41.0.0 was approved, passed CI checks, and successfully merged. Reviewers confirmed Rust version compatibility across all target architectures.
75%
#1098 build(deps): bump cryptography craft-application merged Bumps cryptography from v48.0.0 to v49.0.0 to resolve OSV vulnerability GHSA-537c-gmf6-5ccf. Approved by two reviewers, passed CI checks, and successfully merged.
74%
#4033 build(deps): bump cryptography from 3.4 to 39.0.1 snapcraft closed Closed without merging. A maintainer declined the cryptography version bump because it alone breaks compatibility on certain architectures, recommending a broader update strategy instead.
74%
#4280 build(deps): bump cryptography from 41.0.0 to 41.0.2 snapcraft closed Dependabot PR updating cryptography from 41.0.0 to 41.0.2 was approved and passed CI but closed and superseded by pull request #4301.
74%
#6029 build(deps): bump cryptography from 46.0.3 to 46.0.5 snapcraft merged Merged a Dependabot update bumping cryptography from 46.0.3 to 46.0.5. The upgrade patches CVE-2026-26007, deprecates SECT* curves, and updates OpenSSL to 3.5.5. Approved by two reviewers and merged after passing CI checks.
73%
#86 build(deps): bump cryptography from 46.0.1 to 46.0.5 debcraft merged Merged Dependabot PR updating cryptography from 46.0.1 to 46.0.5. The update patches CVE-2026-26007, upgrades to OpenSSL 3.5.5, and drops win_arm64 wheels. Approved by reviewers and passed all CI checks before merge.
73%
#4301 build(deps): bump cryptography from 41.0.0 to 41.0.3 snapcraft merged Merged Dependabot update upgrading cryptography from 41.0.0 to 41.0.3. The change passed CI checks and reviewer approval, incorporating performance regressions, memory leak fixes, and updated OpenSSL wheels.
73%
#5010 build(deps): update dependency cryptography to v43.0.1 [security] (main) snapcraft merged Merged an automated dependency update upgrading cryptography from 43.0.0 to 43.0.1 to patch a security vulnerability in statically linked OpenSSL wheels. Approved by two reviewers, passed CI, and merged to main.
73%