build(deps): update dependency cryptography to v43 [security] (hotfix/7.5) - autoclosed
Metadata
Current evaluation
Superseded by a newer dependency update and autoclosed by Renovate bot. The security patch updating cryptography to v43 was not manually merged.
Suggested action: —
No scores available.
Issue body
This PR contains the following updates:
| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [cryptography](https://redirect.github.com/pyca/cryptography) ([changelog](https://cryptography.io/en/latest/changelog/)) | `==40.0.2` -> `==43.0.1` | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) |
### GitHub Vulnerability Alerts
#### [GHSA-h4gh-qq45-vh27](https://redirect.github.com/pyca/cryptography/security/advisories/GHSA-h4gh-qq45-vh27)
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt.
If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions.
---
### Release Notes
<details>
<summary>pyca/cryptography (cryptography)</summary>
### [`v43.0.1`](https://redirect.github.com/pyca/cryptography/compare/43.0.0...43.0.1)
[Compare Source](https://redirect.github.com/pyca/cryptography/compare/43.0.0...43.0.1)
### [`v43.0.0`](https://redirect.github.com/pyca/cryptography/compare/42.0.8...43.0.0)
[Compare Source](https://redirect.github.com/pyca/cryptography/compare/42.0.8...43.0.0)
### [`v42.0.8`](https://redirect.github.com/pyca/cryptography/compare/42.0.7...42.0.8)
[Compare Source](https://redirect.github.com/pyca/cryptography/compare/42.0.7...42.0.8)
### [`v42.0.7`](https://redirect.github.com/pyca/cryptography/compare/42.0.6...42.0.7)
[Compare Source](https://redirect.github.com/pyca/cryptography/compare/42.0.6...42.0.7)
### [`v42.0.6`](https://redirect.github.com/pyca/cryptography/compare/42.0.5...42.0.6)
[Compare Source](https://redirect.github.com/pyca/cryptography/compare/42.0.5...42.0.6)
### [`v42.0.5`](https://redirect.github.com/pyca/cryptography/compare/42.0.4...42.0.5)
[Compare Source](https://redirect.github.com/pyca/cryptography/compare/42.0.4...42.0.5)
### [`v42.0.4`](https://redirect.github.com/pyca/cryptography/compare/42.0.3...42.0.4)
[Compare Source](https://redirect.github.com/pyca/cryptography/compare/42.0.3...42.0.4)
### [`v42.0.3`](https://redirect.github.com/pyca/cryptography/compare/42.0.2...42.0.3)
[Compare Source](https://redirect.github.com/pyca/cryptography/compare/42.0.2...42.0.3)
### [`v42.0.2`](https://redirect.github.com/pyca/cryptography/compare/42.0.1...42.0.2)
[Compare Source](https://redirect.github.com/pyca/cryptography/compare/42.0.1...42.0.2)
### [`v42.0.1`](https://redirect.github.com/pyca/cryptography/compare/42.0.0...42.0.1)
[Compare Source](https://redirect.github.com/pyca/cryptography/compare/42.0.0...42.0.1)
### [`v42.0.0`](https://redirect.github.com/pyca/cryptography/compare/41.0.7...42.0.0)
[Compare Source](https://redirect.github.com/pyca/cryptography/compare/41.0.7...42.0.0)
### [`v41.0.7`](https://redirect.github.com/pyca/cryptography/compare/41.0.6...41.0.7)
[Compare Source](https://redirect.github.com/pyca/cryptography/compare/41.0.6...41.0.7)
### [`v41.0.6`](https://redirect.github.com/pyca/cryptography/compare/41.0.5...41.0.6)
[Compare Source](https://redirect.github.com/pyca/cryptography/compare/41.0.5...41.0.6)
### [`v41.0.5`](https://redirect.github.com/pyca/cryptography/compare/41.0.4...41.0.5)
[Compare Source](https://redirect.github.com/pyca/cryptography/compare/41.0.4...41.0.5)
### [`v41.0.4`](https://redirect.github.com/pyca/cryptography/compare/41.0.3...41.0.4)
[Compare Source](https://redirect.github.com/pyca/cryptography/compare/41.0.3...41.0.4)
### [`v41.0.3`](https://redirect.github.com/pyca/cryptography/compare/41.0.2...41.0.3)
[Compare Source](https://redirect.github.com/pyca/cryptography/compare/41.0.2...41.0.3)
### [`v41.0.2`](https://redirect.github.com/pyca/cryptography/compare/41.0.1...41.0.2)
[Compare Source](https://redirect.github.com/pyca/cryptography/compare/41.0.1...41.0.2)
### [`v41.0.1`](https://redirect.github.com/pyca/cryptography/compare/41.0.0...41.0.1)
[Compare Source](https://redirect.github.com/pyca/cryptography/compare/41.0.0...41.0.1)
### [`v41.0.0`](https://redirect.github.com/pyca/cryptography/compare/40.0.2...41.0.0)
[Compare Source](https://redirect.github.com/pyca/cryptography/compare/40.0.2...41.0.0)
</details>
---
### Configuration
📅 **Schedule**: Branch creation - "" in timezone Etc/UTC, Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/canonical/snapcraft).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC41OS4yIiwidXBkYXRlZEluVmVyIjoiMzguNTkuMiIsInRhcmdldEJyYW5jaCI6ImhvdGZpeC83LjUiLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIl19-->
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Superseded by a newer dependency update and autoclosed by Renovate bot. The security patch updating cryptography to v43 was not manually merged. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Dependency update to cryptography v43.0.1 was autoclosed without merging. The branch was abandoned or superseded by another security fix on hotfix/7.5. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Renovate autoclosed the cryptography v43 security update without merging. The dependency change was not applied to the hotfix/7.5 branch. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #5253 build(deps): update dependency cryptography to v44 [security] (hotfix/7.5) - autoclosed | snapcraft | closed | The dependency update pull request for cryptography v44 was autoclosed by Renovate without review or merge. No changes were applied. | |
| #5286 build(deps): update dependency cryptography to v44 [security] (main) - autoclosed | snapcraft | closed | Superseded and autoclosed by Renovate after being replaced by PR #5290. The cryptography dependency update to v44.0.1 was handled in the newer pull request. | |
| #2164 build(deps): update dependency cryptography to v44 [security] (hotfix/2.7) - autoclosed | charmcraft | closed | Security dependency update for cryptography to v44.0.1 via Renovate was autoclosed without review or merge. The pull request was abandoned due to inactivity. | |
| #2570 build(deps): update dependency cryptography to v46 [security] (hotfix/4.1) - autoclosed | charmcraft | closed | Renovate autoclosed this dependency update for cryptography v46 without merging. The PR addressed CVE-2026-26007 but was automatically closed, likely superseded or stale. No manual review occurred. | |
| #2569 build(deps): update dependency cryptography to v46 [security] (hotfix/4.0) - autoclosed | charmcraft | closed | Dependency update for cryptography to v46 addressing CVE-2026-26007 was autoclosed without merging. Renovate discarded the branch, likely due to being superseded or failing CI checks. | |
| #2163 build(deps): update dependency cryptography to v44.0.1 [security] (main) - autoclosed | charmcraft | closed | Autoclosed by Renovate without review or merge. The security update for cryptography to v44.0.1 was abandoned. | |
| #2165 build(deps): update dependency cryptography to v44.0.1 [security] (hotfix/3.3) - autoclosed | charmcraft | closed | The security update PR for cryptography v44.0.1 was autoclosed. The branch was automatically closed, likely because the dependency was already updated or the branch became obsolete, leaving the change unmerged. | |
| #5254 build(deps): update dependency cryptography to v44 [security] (hotfix/8.6) - autoclosed | snapcraft | closed | Renovate pull request updating cryptography to v44.0.1 to address CVE-2024-12797 was autoclosed without review or merge. The security update was abandoned. | |
| #2567 build(deps): update dependency cryptography to v46 [security] (main) - autoclosed | charmcraft | closed | Autoclosed without merging. The Renovate dependency update for cryptography to v46, intended to fix CVE-2026-26007, was abandoned. CI type checks flagged warnings, but the branch was never merged. | |
| #2166 build(deps): update dependency cryptography to v44.0.1 [security] (hotfix/3.4) - autoclosed | charmcraft | closed | Merged and autoclosed after two approvals and passing CI. Updates cryptography to v44.0.1 to resolve CVE-2024-12797. Automerge was enabled, causing automatic closure post-merge. |