build(deps): bump cryptography
Metadata
Current evaluation
Bumps cryptography from v48.0.0 to v49.0.0 to resolve OSV vulnerability GHSA-537c-gmf6-5ccf. Approved by two reviewers, passed CI checks, and successfully merged.
Suggested action: —
No scores available.
Issue body
- [x] Have you followed the guidelines for contributing?
- [x] Have you signed the [CLA](http://www.ubuntu.com/legal/contributors/)?
- [ ] Have you successfully run `make lint && make test`?
- [ ] Have you added an entry to the changelog (`docs/reference/changelog.rst`)?
---
Resolves an [OSV](https://osv.dev/vulnerability/GHSA-537c-gmf6-5ccf)
```
❯ uv lock -P cryptography
Resolved 151 packages in 2.53s
Updated cryptography v48.0.0 -> v49.0.0
```
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Bumps cryptography from v48.0.0 to v49.0.0 to resolve OSV vulnerability GHSA-537c-gmf6-5ccf. Approved by two reviewers, passed CI checks, and successfully merged. | |
| qwen3.6-35b-a3b-mtp-q6 |
Staleness:
0
Complexity:
15
Confidence:
90
|
needs review | Updates cryptography from v48.0.0 to v49.0.0 to resolve OSV vulnerability GHSA-537c-gmf6-5ccf. Awaiting CI checks and changelog entry. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #1055 build(deps): bump cryptography | craft-application | merged | Merged after bumping the cryptography dependency to resolve an OSV security vulnerability. Approved by two reviewers and passed all CI checks, including security scans and multi-platform tests. | |
| #1061 build(deps): bump cryptography | craft-application | merged | Merged a dependency update to bump cryptography, resolving an OSV security vulnerability. Approved by two reviewers and passing all CI checks, the change modified one file with 51 additions and 51 deletions. | |
| #356 build(deps): bump cryptography | craft-store | merged | Merged to bump the cryptography dependency and resolve OSV vulnerability GHSA-p423-j2cm-9vmq. Approved by two reviewers and passed CI checks, with one Windows test failure noted. | |
| #6030 build(deps): bump cryptography from 46.0.3 to 46.0.5 | snapcraft | merged | Merged after review and passing CI checks. Updates the cryptography dependency from 46.0.3 to 46.0.5 to address an OSV security advisory on the hotfix/8.14 branch. | |
| #6029 build(deps): bump cryptography from 46.0.3 to 46.0.5 | snapcraft | merged | Merged a Dependabot update bumping cryptography from 46.0.3 to 46.0.5. The upgrade patches CVE-2026-26007, deprecates SECT* curves, and updates OpenSSL to 3.5.5. Approved by two reviewers and merged after passing CI checks. | |
| #277 build(deps): constrain cryptography to >= 44.0.1 | craft-store | merged | Merged to constrain the cryptography dependency to >= 44.0.1, addressing vulnerability GHSA-79v4-65xg-pq4g. Approved by two reviewers and passing all CI checks, the update was integrated into the codebase. | |
| #6307 build(deps): bump cryptography | snapcraft | merged | Merged after approval. Bumps the cryptography dependency to address a CVE. Core CI checks passed despite some integration and publish job failures. | |
| #86 build(deps): bump cryptography from 46.0.1 to 46.0.5 | debcraft | merged | Merged Dependabot PR updating cryptography from 46.0.1 to 46.0.5. The update patches CVE-2026-26007, upgrades to OpenSSL 3.5.5, and drops win_arm64 wheels. Approved by reviewers and passed all CI checks before merge. | |
| #6163 build(deps): bump cryptography from 46.0.6 to 46.0.7 | snapcraft | merged | Merged Dependabot update bumping cryptography from 46.0.6 to 46.0.7. The release fixes CVE-2026-39892 buffer overflow and updates wheels to OpenSSL 3.5.6. Approved by reviewers and merged after passing core CI checks. | |
| #122 build(deps): bump cryptography from 46.0.6 to 46.0.7 | debcraft | merged | Merged Dependabot update bumping cryptography from 46.0.6 to 46.0.7. Resolves CVE-2026-39892 buffer overflow and updates wheels to OpenSSL 3.5.6. Approved by two reviewers and passed all CI checks. |