← Back to issue list

build(deps): update dependency cryptography to v44 [security] (main)

View original Github issue

Metadata

Project
snapcraft
Number
#5252
Type
pull request
State
closed
Author
renovate[bot]
Labels
Created
Updated
Closed

Current evaluation

Closed without merging as a duplicate of #5251. The cryptography v44 security update was superseded by another PR. Renovate will ignore this update.

Suggested action:

No scores available.

Issue body

This PR contains the following updates: | Package | Change | Age | Adoption | Passing | Confidence | |---|---|---|---|---|---| | [cryptography](https://redirect.github.com/pyca/cryptography) ([changelog](https://cryptography.io/en/latest/changelog/)) | `==43.0.3` -> `==44.0.1` | [![age](https://developer.mend.io/api/mc/badges/age/pypi/cryptography/44.0.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/pypi/cryptography/44.0.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/pypi/cryptography/43.0.3/44.0.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/cryptography/43.0.3/44.0.1?slim=true)](https://docs.renovatebot.com/merge-confidence/) | ### GitHub Vulnerability Alerts #### [CVE-2024-12797](https://redirect.github.com/pyca/cryptography/security/advisories/GHSA-79v4-65xg-pq4g) pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 42.0.0-44.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20250211.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. --- ### Release Notes <details> <summary>pyca/cryptography (cryptography)</summary> ### [`v44.0.1`](https://redirect.github.com/pyca/cryptography/compare/44.0.0...44.0.1) [Compare Source](https://redirect.github.com/pyca/cryptography/compare/44.0.0...44.0.1) ### [`v44.0.0`](https://redirect.github.com/pyca/cryptography/compare/43.0.3...44.0.0) [Compare Source](https://redirect.github.com/pyca/cryptography/compare/43.0.3...44.0.0) </details> --- ### Configuration 📅 **Schedule**: Branch creation - "" in timezone Etc/UTC, Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/canonical/snapcraft). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS4xNjQuMSIsInVwZGF0ZWRJblZlciI6IjM5LjE2NC4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=-->

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Closed without merging as a duplicate of #5251. The cryptography v44 security update was superseded by another PR. Renovate will ignore this update.
qwen3.6-35b-a3b-mtp-q6 Closed without merging as a duplicate of PR #5251. The cryptography v44 security update was superseded by another branch. Renovate will ignore this specific update.
qwen3.6-35b-a3b-mtp-q6 Closed without merging and marked as a duplicate of PR #5251. The cryptography update to v44.0.1 was superseded. Renovate will ignore future updates for this version.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#5285 no build(deps): update dependency cryptography to v44 [security] (main) snapcraft closed Cryptography v44 security update was closed without merging because it was blocked by issue #5217. Renovate will ignore future updates for this version since the PR was manually closed.
92%
#5286 build(deps): update dependency cryptography to v44 [security] (main) - autoclosed snapcraft closed Superseded and autoclosed by Renovate after being replaced by PR #5290. The cryptography dependency update to v44.0.1 was handled in the newer pull request.
91%
#2163 build(deps): update dependency cryptography to v44.0.1 [security] (main) - autoclosed charmcraft closed Autoclosed by Renovate without review or merge. The security update for cryptography to v44.0.1 was abandoned.
89%
#162 build(deps): update dependency cryptography to v49 (main) starflow closed Closed without merging. The automated cryptography v49 update was abandoned, and Renovate will ignore this update. Future minor and patch releases will be skipped unless manually upgraded or the PR is reopened.
89%
#2164 build(deps): update dependency cryptography to v44 [security] (hotfix/2.7) - autoclosed charmcraft closed Security dependency update for cryptography to v44.0.1 via Renovate was autoclosed without review or merge. The pull request was abandoned due to inactivity.
88%
#5253 build(deps): update dependency cryptography to v44 [security] (hotfix/7.5) - autoclosed snapcraft closed The dependency update pull request for cryptography v44 was autoclosed by Renovate without review or merge. No changes were applied.
88%
#2567 build(deps): update dependency cryptography to v46 [security] (main) - autoclosed charmcraft closed Autoclosed without merging. The Renovate dependency update for cryptography to v46, intended to fix CVE-2026-26007, was abandoned. CI type checks flagged warnings, but the branch was never merged.
86%
#5254 build(deps): update dependency cryptography to v44 [security] (hotfix/8.6) - autoclosed snapcraft closed Renovate pull request updating cryptography to v44.0.1 to address CVE-2024-12797 was autoclosed without review or merge. The security update was abandoned.
85%
#5011 build(deps): update dependency cryptography to v43 [security] (hotfix/7.5) - autoclosed snapcraft closed Superseded by a newer dependency update and autoclosed by Renovate bot. The security patch updating cryptography to v43 was not manually merged.
85%
#2570 build(deps): update dependency cryptography to v46 [security] (hotfix/4.1) - autoclosed charmcraft closed Renovate autoclosed this dependency update for cryptography v46 without merging. The PR addressed CVE-2026-26007 but was automatically closed, likely superseded or stale. No manual review occurred.
84%