build(deps): update dependency cryptography to v43.0.1 [security] (hotfix/3.2)
Metadata
Current evaluation
Merged security hotfix updating cryptography from v43.0.0 to v43.0.1 on hotfix/3.2. Addresses OpenSSL vulnerability GHSA-h4gh-qq45-vh27 in pre-built wheels. Approved by two reviewers and passed CI checks prior to merge.
Suggested action: —
No scores available.
Issue body
This PR contains the following updates:
| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [cryptography](https://redirect.github.com/pyca/cryptography) ([changelog](https://cryptography.io/en/latest/changelog/)) | `==43.0.0` -> `==43.0.1` | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) |
### GitHub Vulnerability Alerts
#### [GHSA-h4gh-qq45-vh27](https://redirect.github.com/pyca/cryptography/security/advisories/GHSA-h4gh-qq45-vh27)
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt.
If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions.
---
### Release Notes
<details>
<summary>pyca/cryptography (cryptography)</summary>
### [`v43.0.1`](https://redirect.github.com/pyca/cryptography/compare/43.0.0...43.0.1)
[Compare Source](https://redirect.github.com/pyca/cryptography/compare/43.0.0...43.0.1)
</details>
---
### Configuration
📅 **Schedule**: Branch creation - "" in timezone Etc/UTC, Automerge - At any time (no schedule defined).
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/canonical/charmcraft).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC41OS4yIiwidXBkYXRlZEluVmVyIjoiMzguNTkuMiIsInRhcmdldEJyYW5jaCI6ImhvdGZpeC8zLjIiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19-->
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Merged security hotfix updating cryptography from v43.0.0 to v43.0.1 on hotfix/3.2. Addresses OpenSSL vulnerability GHSA-h4gh-qq45-vh27 in pre-built wheels. Approved by two reviewers and passed CI checks prior to merge. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged security hotfix updating cryptography to v43.0.1 on hotfix/3.2. Patches GHSA-h4gh-qq45-vh27 OpenSSL vulnerability in prebuilt wheels. Automated via Renovate bot. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged automated dependency update upgrading cryptography to v43.0.1 on hotfix/3.2 to patch an OpenSSL wheel vulnerability. Renovate auto-merged after checks passed, noting an unrelated snap test failure. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #1871 build(deps): update dependency cryptography to v43 [security] (hotfix/2.7) | charmcraft | merged | Merged to hotfix/2.7, updating cryptography from v41.0.7 to v43.0.1 to resolve GHSA-h4gh-qq45-vh27 OpenSSL wheel vulnerability. Approved by two reviewers, passed CI, and successfully merged. | |
| #1870 build(deps): update dependency cryptography to v43.0.1 [security] (main) | charmcraft | merged | Merged automated dependency update to cryptography v43.0.1 to address a security vulnerability in OpenSSL wheels. Approved by two reviewers, passed CI checks, and merged to main. | |
| #5010 build(deps): update dependency cryptography to v43.0.1 [security] (main) | snapcraft | merged | Merged an automated dependency update upgrading cryptography from 43.0.0 to 43.0.1 to patch a security vulnerability in statically linked OpenSSL wheels. Approved by two reviewers, passed CI, and merged to main. | |
| #1271 build(deps): bump cryptography from 41.0.3 to 41.0.4 | charmcraft | merged | Dependabot merged a dependency update bumping cryptography from 41.0.3 to 41.0.4. Approved by two reviewers and passing CI, the change updates two files and includes OpenSSL 3.1.3 wheel compilation. | |
| #2166 build(deps): update dependency cryptography to v44.0.1 [security] (hotfix/3.4) - autoclosed | charmcraft | closed | Merged and autoclosed after two approvals and passing CI. Updates cryptography to v44.0.1 to resolve CVE-2024-12797. Automerge was enabled, causing automatic closure post-merge. | |
| #4301 build(deps): bump cryptography from 41.0.0 to 41.0.3 | snapcraft | merged | Merged Dependabot update upgrading cryptography from 41.0.0 to 41.0.3. The change passed CI checks and reviewer approval, incorporating performance regressions, memory leak fixes, and updated OpenSSL wheels. | |
| #4374 build(deps): bump cryptography from 41.0.3 to 41.0.4 | snapcraft | merged | Dependabot automated update bumped cryptography from 41.0.3 to 41.0.4. Approved by two reviewers, passed CI, and merged. The release compiles wheels with OpenSSL 3.1.3 and caused no coverage changes. | |
| #86 build(deps): bump cryptography from 46.0.1 to 46.0.5 | debcraft | merged | Merged Dependabot PR updating cryptography from 46.0.1 to 46.0.5. The update patches CVE-2026-26007, upgrades to OpenSSL 3.5.5, and drops win_arm64 wheels. Approved by reviewers and passed all CI checks before merge. | |
| #2165 build(deps): update dependency cryptography to v44.0.1 [security] (hotfix/3.3) - autoclosed | charmcraft | closed | The security update PR for cryptography v44.0.1 was autoclosed. The branch was automatically closed, likely because the dependency was already updated or the branch became obsolete, leaving the change unmerged. | |
| #277 build(deps): constrain cryptography to >= 44.0.1 | craft-store | merged | Merged to constrain the cryptography dependency to >= 44.0.1, addressing vulnerability GHSA-79v4-65xg-pq4g. Approved by two reviewers and passing all CI checks, the update was integrated into the codebase. |