← Back to issue list

build(deps): update dependency cryptography to v43.0.1 [security] (hotfix/3.2)

View original Github issue

Metadata

Project
charmcraft
Number
#1872
Type
pull request
State
merged
Author
renovate[bot]
Labels
Created
Updated
Closed

Current evaluation

Merged security hotfix updating cryptography from v43.0.0 to v43.0.1 on hotfix/3.2. Addresses OpenSSL vulnerability GHSA-h4gh-qq45-vh27 in pre-built wheels. Approved by two reviewers and passed CI checks prior to merge.

Suggested action:

No scores available.

Issue body

This PR contains the following updates: | Package | Change | Age | Adoption | Passing | Confidence | |---|---|---|---|---|---| | [cryptography](https://redirect.github.com/pyca/cryptography) ([changelog](https://cryptography.io/en/latest/changelog/)) | `==43.0.0` -> `==43.0.1` | [![age](https://developer.mend.io/api/mc/badges/age/pypi/cryptography/43.0.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/pypi/cryptography/43.0.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/pypi/cryptography/43.0.0/43.0.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/cryptography/43.0.0/43.0.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | ### GitHub Vulnerability Alerts #### [GHSA-h4gh-qq45-vh27](https://redirect.github.com/pyca/cryptography/security/advisories/GHSA-h4gh-qq45-vh27) pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. --- ### Release Notes <details> <summary>pyca/cryptography (cryptography)</summary> ### [`v43.0.1`](https://redirect.github.com/pyca/cryptography/compare/43.0.0...43.0.1) [Compare Source](https://redirect.github.com/pyca/cryptography/compare/43.0.0...43.0.1) </details> --- ### Configuration 📅 **Schedule**: Branch creation - "" in timezone Etc/UTC, Automerge - At any time (no schedule defined). 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/canonical/charmcraft). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC41OS4yIiwidXBkYXRlZEluVmVyIjoiMzguNTkuMiIsInRhcmdldEJyYW5jaCI6ImhvdGZpeC8zLjIiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19-->

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Merged security hotfix updating cryptography from v43.0.0 to v43.0.1 on hotfix/3.2. Addresses OpenSSL vulnerability GHSA-h4gh-qq45-vh27 in pre-built wheels. Approved by two reviewers and passed CI checks prior to merge.
qwen3.6-35b-a3b-mtp-q6 Merged security hotfix updating cryptography to v43.0.1 on hotfix/3.2. Patches GHSA-h4gh-qq45-vh27 OpenSSL vulnerability in prebuilt wheels. Automated via Renovate bot.
qwen3.6-35b-a3b-mtp-q6 Merged automated dependency update upgrading cryptography to v43.0.1 on hotfix/3.2 to patch an OpenSSL wheel vulnerability. Renovate auto-merged after checks passed, noting an unrelated snap test failure.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#1871 build(deps): update dependency cryptography to v43 [security] (hotfix/2.7) charmcraft merged Merged to hotfix/2.7, updating cryptography from v41.0.7 to v43.0.1 to resolve GHSA-h4gh-qq45-vh27 OpenSSL wheel vulnerability. Approved by two reviewers, passed CI, and successfully merged.
96%
#1870 build(deps): update dependency cryptography to v43.0.1 [security] (main) charmcraft merged Merged automated dependency update to cryptography v43.0.1 to address a security vulnerability in OpenSSL wheels. Approved by two reviewers, passed CI checks, and merged to main.
92%
#5010 build(deps): update dependency cryptography to v43.0.1 [security] (main) snapcraft merged Merged an automated dependency update upgrading cryptography from 43.0.0 to 43.0.1 to patch a security vulnerability in statically linked OpenSSL wheels. Approved by two reviewers, passed CI, and merged to main.
92%
#1271 build(deps): bump cryptography from 41.0.3 to 41.0.4 charmcraft merged Dependabot merged a dependency update bumping cryptography from 41.0.3 to 41.0.4. Approved by two reviewers and passing CI, the change updates two files and includes OpenSSL 3.1.3 wheel compilation.
85%
#2166 build(deps): update dependency cryptography to v44.0.1 [security] (hotfix/3.4) - autoclosed charmcraft closed Merged and autoclosed after two approvals and passing CI. Updates cryptography to v44.0.1 to resolve CVE-2024-12797. Automerge was enabled, causing automatic closure post-merge.
84%
#4301 build(deps): bump cryptography from 41.0.0 to 41.0.3 snapcraft merged Merged Dependabot update upgrading cryptography from 41.0.0 to 41.0.3. The change passed CI checks and reviewer approval, incorporating performance regressions, memory leak fixes, and updated OpenSSL wheels.
84%
#4374 build(deps): bump cryptography from 41.0.3 to 41.0.4 snapcraft merged Dependabot automated update bumped cryptography from 41.0.3 to 41.0.4. Approved by two reviewers, passed CI, and merged. The release compiles wheels with OpenSSL 3.1.3 and caused no coverage changes.
83%
#86 build(deps): bump cryptography from 46.0.1 to 46.0.5 debcraft merged Merged Dependabot PR updating cryptography from 46.0.1 to 46.0.5. The update patches CVE-2026-26007, upgrades to OpenSSL 3.5.5, and drops win_arm64 wheels. Approved by reviewers and passed all CI checks before merge.
83%
#2165 build(deps): update dependency cryptography to v44.0.1 [security] (hotfix/3.3) - autoclosed charmcraft closed The security update PR for cryptography v44.0.1 was autoclosed. The branch was automatically closed, likely because the dependency was already updated or the branch became obsolete, leaving the change unmerged.
82%
#277 build(deps): constrain cryptography to >= 44.0.1 craft-store merged Merged to constrain the cryptography dependency to >= 44.0.1, addressing vulnerability GHSA-79v4-65xg-pq4g. Approved by two reviewers and passing all CI checks, the update was integrated into the codebase.
82%