chore(deps): update dependency cryptography to v39
Metadata
Current evaluation
Closed unmerged due to incompatible Rust version requirements for Ubuntu 18.04/20.04 snap platforms. The update was deferred until build environments support the necessary toolchain. Renovate will skip v39.
Suggested action: —
No scores available.
Issue body
[](https://renovatebot.com)
This PR contains the following updates:
| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [cryptography](https://togithub.com/pyca/cryptography) ([changelog](https://cryptography.io/en/latest/changelog/)) | `==3.4.8` -> `==39.0.0` | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) |
---
### Release Notes
<details>
<summary>pyca/cryptography</summary>
### [`v39.0.0`](https://togithub.com/pyca/cryptography/compare/38.0.4...39.0.0)
[Compare Source](https://togithub.com/pyca/cryptography/compare/38.0.4...39.0.0)
### [`v38.0.4`](https://togithub.com/pyca/cryptography/compare/38.0.3...38.0.4)
[Compare Source](https://togithub.com/pyca/cryptography/compare/38.0.3...38.0.4)
### [`v38.0.3`](https://togithub.com/pyca/cryptography/compare/38.0.2...38.0.3)
[Compare Source](https://togithub.com/pyca/cryptography/compare/38.0.2...38.0.3)
### [`v38.0.2`](https://togithub.com/pyca/cryptography/compare/38.0.1...38.0.2)
[Compare Source](https://togithub.com/pyca/cryptography/compare/38.0.1...38.0.2)
### [`v38.0.1`](https://togithub.com/pyca/cryptography/compare/38.0.0...38.0.1)
[Compare Source](https://togithub.com/pyca/cryptography/compare/38.0.0...38.0.1)
### [`v38.0.0`](https://togithub.com/pyca/cryptography/compare/37.0.4...38.0.0)
[Compare Source](https://togithub.com/pyca/cryptography/compare/37.0.4...38.0.0)
### [`v37.0.4`](https://togithub.com/pyca/cryptography/compare/37.0.3...37.0.4)
[Compare Source](https://togithub.com/pyca/cryptography/compare/37.0.3...37.0.4)
### [`v37.0.3`](https://togithub.com/pyca/cryptography/compare/37.0.2...37.0.3)
[Compare Source](https://togithub.com/pyca/cryptography/compare/37.0.2...37.0.3)
### [`v37.0.2`](https://togithub.com/pyca/cryptography/compare/37.0.1...37.0.2)
[Compare Source](https://togithub.com/pyca/cryptography/compare/37.0.1...37.0.2)
### [`v37.0.1`](https://togithub.com/pyca/cryptography/compare/37.0.0...37.0.1)
[Compare Source](https://togithub.com/pyca/cryptography/compare/37.0.0...37.0.1)
### [`v37.0.0`](https://togithub.com/pyca/cryptography/compare/36.0.2...37.0.0)
[Compare Source](https://togithub.com/pyca/cryptography/compare/36.0.2...37.0.0)
### [`v36.0.2`](https://togithub.com/pyca/cryptography/compare/36.0.1...36.0.2)
[Compare Source](https://togithub.com/pyca/cryptography/compare/36.0.1...36.0.2)
### [`v36.0.1`](https://togithub.com/pyca/cryptography/compare/36.0.0...36.0.1)
[Compare Source](https://togithub.com/pyca/cryptography/compare/36.0.0...36.0.1)
### [`v36.0.0`](https://togithub.com/pyca/cryptography/compare/35.0.0...36.0.0)
[Compare Source](https://togithub.com/pyca/cryptography/compare/35.0.0...36.0.0)
### [`v35.0.0`](https://togithub.com/pyca/cryptography/compare/3.4.8...35.0.0)
[Compare Source](https://togithub.com/pyca/cryptography/compare/3.4.8...35.0.0)
</details>
---
### Configuration
📅 **Schedule**: Branch creation - "every weekend" in timezone Etc/UTC, Automerge - "after 1 am and before 7 am" in timezone Etc/UTC.
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about these updates again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://app.renovatebot.com/dashboard#github/canonical/charmcraft).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNC44NC4yIiwidXBkYXRlZEluVmVyIjoiMzQuODQuMiJ9-->
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Closed unmerged due to incompatible Rust version requirements for Ubuntu 18.04/20.04 snap platforms. The update was deferred until build environments support the necessary toolchain. Renovate will skip v39. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Updating cryptography to v39 was closed without merging. Maintainers deferred the upgrade due to Rust dependency conflicts with older Ubuntu snap platforms, pending infrastructure updates. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Closed unmerged due to Rust dependency incompatibility with older Ubuntu snap platforms. The update was deferred until snap environments support the required Rust version. Renovate will ignore future v39.x releases. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #1056 chore(deps): update dependency cryptography to v39 [security] | charmcraft | closed | Closed unmerged and superseded by PR #1024, which addresses the cryptography v39 security update. Renovate will ignore future 39.x releases for this branch. | |
| #1537 chore(deps): update dependency cryptography to v42.0.4 [security] | charmcraft | closed | Maintainer closed the cryptography v42.0.4 security update without merging. The patch requires an environment variable change and will be handled separately. Renovate will ignore this specific version. | |
| #1019 chore(deps): update dependency cryptography to v39 [security] | charmcraft | closed | Superseded by PR #1024. The automated cryptography v39 security update was closed unmerged to prevent duplication with a newer dependency upgrade. | |
| #1272 chore(deps): update dependency cryptography to v41.0.4 [security] | charmcraft | closed | Closed without merging after failing a flaky store test. Superseded by PR #1271. Renovate will ignore this cryptography v41.0.4 update until a newer version is released. | |
| #1164 chore(deps): update dependency cryptography to v41.0.2 [security] | charmcraft | merged | Merged automated dependency update upgrading cryptography from v41.0.0 to v41.0.2 to resolve CVE-2023-38325 SSH certificate vulnerability. Approved, passed CI checks, and successfully merged via Renovate bot. | |
| #1396 chore(deps): update dependency cryptography to v41.0.6 [security] | charmcraft | merged | Merged automated dependency update upgrading cryptography from 41.0.4 to 41.0.6 to resolve CVE-2023-49083, preventing a denial of service from NULL-pointer dereference during PKCS7 parsing. Approved and merged automatically by Renovate. | |
| #1120 chore(deps): update dependency cryptography to v41 [security] - autoclosed | charmcraft | closed | The cryptography v41 security update pull request was autoclosed without merging. Renovate automatically closed it due to inactivity or because the dependency was already updated. No reviews or CI checks were performed. | |
| #1057 chore(deps): update dependency cryptography [security] - autoclosed | charmcraft | closed | Security update for cryptography was autoclosed by Renovate without merging. The bot is configured to automatically recreate the PR upon closure. | |
| #87 chore(deps): update dependency canonical/snapcraft to v8.9.5 (core22-8) | snapcraft-rocks | closed | Closed without merging and superseded by another update. Renovate will ignore this dependency bump to canonical/snapcraft v8.9.5 until a newer version is released. | |
| #4564 chore(deps): update dependency cryptography to v42 [security] | snapcraft | merged | Merged automated dependency update upgrading cryptography from v41.0.7 to v42.0.2 to patch CVE-2023-50782 and CVE-2024-0727. The change passed CI checks, received two approvals, and was merged into main. |