build(deps): constrain cryptography to >= 44.0.1
Metadata
Current evaluation
Merged to constrain the cryptography dependency to >= 44.0.1, addressing vulnerability GHSA-79v4-65xg-pq4g. Approved by two reviewers and passing all CI checks, the update was integrated into the codebase.
Suggested action: —
No scores available.
Issue body
Prevents https://osv.dev/vulnerability/GHSA-79v4-65xg-pq4g
- [x] Have you followed the guidelines for contributing?
- [x] Have you signed the [CLA](http://www.ubuntu.com/legal/contributors/)?
- [x] Have you successfully run `make lint && make test`?
-----
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Merged to constrain the cryptography dependency to >= 44.0.1, addressing vulnerability GHSA-79v4-65xg-pq4g. Approved by two reviewers and passing all CI checks, the update was integrated into the codebase. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Merged PR constraining the cryptography dependency to >= 44.0.1 to prevent vulnerability GHSA-79v4-65xg-pq4g. All checks passed and the change was integrated. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #1098 build(deps): bump cryptography | craft-application | merged | Bumps cryptography from v48.0.0 to v49.0.0 to resolve OSV vulnerability GHSA-537c-gmf6-5ccf. Approved by two reviewers, passed CI checks, and successfully merged. | |
| #1871 build(deps): update dependency cryptography to v43 [security] (hotfix/2.7) | charmcraft | merged | Merged to hotfix/2.7, updating cryptography from v41.0.7 to v43.0.1 to resolve GHSA-h4gh-qq45-vh27 OpenSSL wheel vulnerability. Approved by two reviewers, passed CI, and successfully merged. | |
| #2162 build(deps-dev): bump cryptography from 44.0.0 to 44.0.1 | charmcraft | merged | Merged a Dependabot update bumping the cryptography dependency from 44.0.0 to 44.0.1. The change was approved, passed CI checks, and successfully merged into the codebase. | |
| #1872 build(deps): update dependency cryptography to v43.0.1 [security] (hotfix/3.2) | charmcraft | merged | Merged security hotfix updating cryptography from v43.0.0 to v43.0.1 on hotfix/3.2. Addresses OpenSSL vulnerability GHSA-h4gh-qq45-vh27 in pre-built wheels. Approved by two reviewers and passed CI checks prior to merge. | |
| #1870 build(deps): update dependency cryptography to v43.0.1 [security] (main) | charmcraft | merged | Merged automated dependency update to cryptography v43.0.1 to address a security vulnerability in OpenSSL wheels. Approved by two reviewers, passed CI checks, and merged to main. | |
| #1061 build(deps): bump cryptography | craft-application | merged | Merged a dependency update to bump cryptography, resolving an OSV security vulnerability. Approved by two reviewers and passing all CI checks, the change modified one file with 51 additions and 51 deletions. | |
| #5010 build(deps): update dependency cryptography to v43.0.1 [security] (main) | snapcraft | merged | Merged an automated dependency update upgrading cryptography from 43.0.0 to 43.0.1 to patch a security vulnerability in statically linked OpenSSL wheels. Approved by two reviewers, passed CI, and merged to main. | |
| #6029 build(deps): bump cryptography from 46.0.3 to 46.0.5 | snapcraft | merged | Merged a Dependabot update bumping cryptography from 46.0.3 to 46.0.5. The upgrade patches CVE-2026-26007, deprecates SECT* curves, and updates OpenSSL to 3.5.5. Approved by two reviewers and merged after passing CI checks. | |
| #2166 build(deps): update dependency cryptography to v44.0.1 [security] (hotfix/3.4) - autoclosed | charmcraft | closed | Merged and autoclosed after two approvals and passing CI. Updates cryptography to v44.0.1 to resolve CVE-2024-12797. Automerge was enabled, causing automatic closure post-merge. | |
| #1055 build(deps): bump cryptography | craft-application | merged | Merged after bumping the cryptography dependency to resolve an OSV security vulnerability. Approved by two reviewers and passed all CI checks, including security scans and multi-platform tests. |