← Back to issue list

build(deps): bump cryptography

View original Github issue

Metadata

Project
craft-application
Number
#1098
Type
pull request
State
merged
Author
smethnani
Labels
Created
Updated
Closed

Current evaluation

Bumps cryptography from v48.0.0 to v49.0.0 to resolve OSV vulnerability GHSA-537c-gmf6-5ccf. Approved by two reviewers, passed CI checks, and successfully merged.

Suggested action:

No scores available.

Issue body

- [x] Have you followed the guidelines for contributing? - [x] Have you signed the [CLA](http://www.ubuntu.com/legal/contributors/)? - [ ] Have you successfully run `make lint && make test`? - [ ] Have you added an entry to the changelog (`docs/reference/changelog.rst`)? --- Resolves an [OSV](https://osv.dev/vulnerability/GHSA-537c-gmf6-5ccf) ``` ❯ uv lock -P cryptography Resolved 151 packages in 2.53s Updated cryptography v48.0.0 -> v49.0.0 ```

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Bumps cryptography from v48.0.0 to v49.0.0 to resolve OSV vulnerability GHSA-537c-gmf6-5ccf. Approved by two reviewers, passed CI checks, and successfully merged.
qwen3.6-35b-a3b-mtp-q6
Staleness: 0
Complexity: 15
Confidence: 90
needs review Updates cryptography from v48.0.0 to v49.0.0 to resolve OSV vulnerability GHSA-537c-gmf6-5ccf. Awaiting CI checks and changelog entry.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#1055 build(deps): bump cryptography craft-application merged Merged after bumping the cryptography dependency to resolve an OSV security vulnerability. Approved by two reviewers and passed all CI checks, including security scans and multi-platform tests.
90%
#1061 build(deps): bump cryptography craft-application merged Merged a dependency update to bump cryptography, resolving an OSV security vulnerability. Approved by two reviewers and passing all CI checks, the change modified one file with 51 additions and 51 deletions.
89%
#356 build(deps): bump cryptography craft-store merged Merged to bump the cryptography dependency and resolve OSV vulnerability GHSA-p423-j2cm-9vmq. Approved by two reviewers and passed CI checks, with one Windows test failure noted.
89%
#6030 build(deps): bump cryptography from 46.0.3 to 46.0.5 snapcraft merged Merged after review and passing CI checks. Updates the cryptography dependency from 46.0.3 to 46.0.5 to address an OSV security advisory on the hotfix/8.14 branch.
87%
#6029 build(deps): bump cryptography from 46.0.3 to 46.0.5 snapcraft merged Merged a Dependabot update bumping cryptography from 46.0.3 to 46.0.5. The upgrade patches CVE-2026-26007, deprecates SECT* curves, and updates OpenSSL to 3.5.5. Approved by two reviewers and merged after passing CI checks.
87%
#277 build(deps): constrain cryptography to >= 44.0.1 craft-store merged Merged to constrain the cryptography dependency to >= 44.0.1, addressing vulnerability GHSA-79v4-65xg-pq4g. Approved by two reviewers and passing all CI checks, the update was integrated into the codebase.
87%
#6307 build(deps): bump cryptography snapcraft merged Merged after approval. Bumps the cryptography dependency to address a CVE. Core CI checks passed despite some integration and publish job failures.
85%
#86 build(deps): bump cryptography from 46.0.1 to 46.0.5 debcraft merged Merged Dependabot PR updating cryptography from 46.0.1 to 46.0.5. The update patches CVE-2026-26007, upgrades to OpenSSL 3.5.5, and drops win_arm64 wheels. Approved by reviewers and passed all CI checks before merge.
85%
#6163 build(deps): bump cryptography from 46.0.6 to 46.0.7 snapcraft merged Merged Dependabot update bumping cryptography from 46.0.6 to 46.0.7. The release fixes CVE-2026-39892 buffer overflow and updates wheels to OpenSSL 3.5.6. Approved by reviewers and merged after passing core CI checks.
85%
#122 build(deps): bump cryptography from 46.0.6 to 46.0.7 debcraft merged Merged Dependabot update bumping cryptography from 46.0.6 to 46.0.7. Resolves CVE-2026-39892 buffer overflow and updates wheels to OpenSSL 3.5.6. Approved by two reviewers and passed all CI checks.
85%