← Back to issue list

build(deps): bump cryptography from 46.0.3 to 46.0.5

View original Github issue

Metadata

Project
snapcraft
Number
#6030
Type
pull request
State
merged
Author
mr-cal
Labels
Created
Updated
Closed

Current evaluation

Merged after review and passing CI checks. Updates the cryptography dependency from 46.0.3 to 46.0.5 to address an OSV security advisory on the hotfix/8.14 branch.

Suggested action:

No scores available.

Issue body

Bumps cryptography for hotfix/8.14 for an OSV. --- - [x] I've followed the [contribution guidelines](https://github.com/canonical/snapcraft/blob/main/CONTRIBUTING.md). - [x] I've signed the [CLA](http://www.ubuntu.com/legal/contributors/). - [ ] I've successfully run `make lint && make test`. - [ ] I've added or updated any relevant documentation. - [ ] I've updated the relevant release notes.

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Merged after review and passing CI checks. Updates the cryptography dependency from 46.0.3 to 46.0.5 to address an OSV security advisory on the hotfix/8.14 branch.
qwen3.6-35b-a3b-mtp-q6 Merged dependency update bumping cryptography from 46.0.3 to 46.0.5 to address an OSV security advisory on the hotfix/8.14 branch. The maintainer-submitted change was accepted and merged without additional comments or documentation updates.
qwen3.6-35b-a3b-mtp-q6 Merged bumping cryptography from 46.0.3 to 46.0.5 to patch an OSV vulnerability on the hotfix/8.14 branch. Maintainer mr-cal submitted the update, which was integrated without conflicts or comments.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#6029 build(deps): bump cryptography from 46.0.3 to 46.0.5 snapcraft merged Merged a Dependabot update bumping cryptography from 46.0.3 to 46.0.5. The upgrade patches CVE-2026-26007, deprecates SECT* curves, and updates OpenSSL to 3.5.5. Approved by two reviewers and merged after passing CI checks.
88%
#318 build: bump cryptography to 46.0.7 imagecraft merged Merged a dependency update bumping cryptography to 46.0.7 to resolve an OSV security advisory. Approved by two reviewers, the change was merged despite failing spread tests on older Ubuntu releases.
87%
#86 build(deps): bump cryptography from 46.0.1 to 46.0.5 debcraft merged Merged Dependabot PR updating cryptography from 46.0.1 to 46.0.5. The update patches CVE-2026-26007, upgrades to OpenSSL 3.5.5, and drops win_arm64 wheels. Approved by reviewers and passed all CI checks before merge.
87%
#1098 build(deps): bump cryptography craft-application merged Bumps cryptography from v48.0.0 to v49.0.0 to resolve OSV vulnerability GHSA-537c-gmf6-5ccf. Approved by two reviewers, passed CI checks, and successfully merged.
87%
#6163 build(deps): bump cryptography from 46.0.6 to 46.0.7 snapcraft merged Merged Dependabot update bumping cryptography from 46.0.6 to 46.0.7. The release fixes CVE-2026-39892 buffer overflow and updates wheels to OpenSSL 3.5.6. Approved by reviewers and merged after passing core CI checks.
86%
#1061 build(deps): bump cryptography craft-application merged Merged a dependency update to bump cryptography, resolving an OSV security vulnerability. Approved by two reviewers and passing all CI checks, the change modified one file with 51 additions and 51 deletions.
85%
#6135 build(deps): bump cryptography from 46.0.5 to 46.0.6 snapcraft merged Merged Dependabot update bumping cryptography from 46.0.5 to 46.0.6. Fixes CVE-2026-34073, addressing a vulnerability where name constraints were skipped for peer names with wildcard DNS SANs. Approved and passed CI.
85%
#122 build(deps): bump cryptography from 46.0.6 to 46.0.7 debcraft merged Merged Dependabot update bumping cryptography from 46.0.6 to 46.0.7. Resolves CVE-2026-39892 buffer overflow and updates wheels to OpenSSL 3.5.6. Approved by two reviewers and passed all CI checks.
84%
#1055 build(deps): bump cryptography craft-application merged Merged after bumping the cryptography dependency to resolve an OSV security vulnerability. Approved by two reviewers and passed all CI checks, including security scans and multi-platform tests.
84%
#2569 build(deps): update dependency cryptography to v46 [security] (hotfix/4.0) - autoclosed charmcraft closed Dependency update for cryptography to v46 addressing CVE-2026-26007 was autoclosed without merging. Renovate discarded the branch, likely due to being superseded or failing CI checks.
84%