chore(deps): bump cryptography from 48.0.1 to 50.0.0 in /envs/sophistry_bench_sprint_env - #1065
Conversation
Bumps [cryptography](https://github.com/pyca/cryptography) from 48.0.1 to 50.0.0. - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@48.0.1...50.0.0) --- updated-dependencies: - dependency-name: cryptography dependency-version: 50.0.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
|
The docs for this PR live here. All of your documentation changes will be reflected on that endpoint. The docs are available until 30 days after the last update. |
There was a problem hiding this comment.
Alignment Review Report
Two-tier automated review of this Dependabot bump. Scope: the PR touches exactly one file — envs/sophistry_bench_sprint_env/uv.lock (no .py, pyproject.toml, openenv.yaml, or Dockerfile changes). Only one package version actually changes: cryptography 48.0.1 → 50.0.0.
Automated Checks
- Lint (
.claude/hooks/lint.sh): FAIL — but pre-existing and unrelated to this PR. The failures areruff formatdiffs in ~26 files across other envs (e.g.opencode_env,pi_env,chat_env,coding_tools_env,jupyter_env,repl_env,terminus_env,textarena_env,agent_world_model_env). Nothing undersophistry_bench_sprint_env/and nothing in this diff is implicated. - Debug code (
.claude/hooks/check-debug.sh): FOUND — but all insrc/openenv/**(docstring examples, Rich console output, a standalonetest_local_docker_provider.py, and 3 pre-existing TODOs). None are in this diff.
Net: this PR introduces zero new lint or debug issues.
Open RFCs Context
RFCs 000/001/002/003/005 are In Review, 010 is Draft, and 004 has no status line. None govern Python dependency management, PyPI index selection, or lockfiles (RFC 002's "Dependency Management" section is about Docker Compose sim/prod, and its "registry" references are to container/tool registries). No RFC is in scope for this change.
Tier 1: Fixes Required
None attributable to this PR. The lint/debug findings above reflect pre-existing repo state; fixing them inside a lockfile-only Dependabot bump would be scope creep.
Tier 2: Alignment Discussion
Principle Conflicts
ALIGNMENT FLAG: Lockfile-wide package index switch (HF internal registry → public PyPI)
- Principle/Invariant at stake: PRINCIPLES.md → "Container isolation for reproducibility and security"; INVARIANTS.md → Security Invariants ("Network access must be explicitly configured").
- The concern: Beyond the intended
cryptographybump, this regeneration flips thesourceregistry for all 166 packages fromhttps://pypi.registries.huggingface.tech/tohttps://pypi.org/simple, and bumps the lockrevision2 → 3. This is almost certainly a side effect of Dependabot resolving without the HF internal index configured, rather than an intentional decision. Integrity risk is low here (every wheel/sdist keeps a pinnedsha256and artifact URLs remainfiles.pythonhosted.org), but it does change this env's resolution source of truth and will churn back on the next in-infrauv lock. Note the repo is already split (~16 envs on the HF registry, ~22 on pypi.org — including the referenceecho_env), so pypi.org may be perfectly acceptable; the team should just confirm the intended index forsophistry_bench_sprint_envand, if HF is intended, ensure Dependabot is configured with it. - Suggested reviewer: @Darktex (git blame attributes both the security invariants and the container-isolation principle to them) — plus the env owner (added in #787).
RFC Conflicts
None identified.
Summary
- 0 mechanical issues to fix (from this PR)
- 1 alignment point for human review (whole-lockfile index/registry churn)
- 0 RFC conflicts
FYI (security-positive, not a blocker): cryptography 50.0.0 (released 2026-07-31) patches CVE-2026-69247 — a Bleichenbacher oracle in PKCS#7 decryption affecting >=44.0.0,<50.0.0, i.e. the current 48.0.1 is vulnerable. It is a major jump (48 → 50) that deprecates FFDH; uv resolved it cleanly against the transitive consumers (authlib, joserfc, secretstorage), so there is no constraint break — a green CI run is the only runtime caveat before merge.
Sent by Cursor Automation: Pre-review
| @@ -849,68 +849,65 @@ toml = [ | |||
|
|
|||
| [[package]] | |||
| name = "cryptography" | |||
| version = "48.0.1" | |||
| source = { registry = "https://pypi.registries.huggingface.tech/" } | |||
| version = "50.0.0" | |||
There was a problem hiding this comment.
Intended change. cryptography 50.0.0 (released 2026-07-31) patches CVE-2026-69247 (a Bleichenbacher oracle in PKCS#7 decryption; affected range >=44.0.0,<50.0.0, so the prior 48.0.1 was vulnerable) — so this is security-positive. It is a major bump (deprecates FFDH over finite fields). uv resolved it against the transitive consumers (authlib, joserfc, secretstorage) with no constraint break, so a green CI run before merge is the only runtime caveat.
| version = "48.0.1" | ||
| source = { registry = "https://pypi.registries.huggingface.tech/" } | ||
| version = "50.0.0" | ||
| source = { registry = "https://pypi.org/simple" } |
There was a problem hiding this comment.
Tier 2 (alignment) — flagging for discussion, not a blocker: this line is one of 166 packages whose source flips from pypi.registries.huggingface.tech → pypi.org/simple in this regeneration (alongside revision 2 → 3). The whole lockfile's package index changed, not just cryptography. This is almost certainly a Dependabot side effect (it resolved without the HF internal index configured). Integrity is still protected (pinned sha256 + files.pythonhosted.org artifact URLs), but please confirm the intended index for this env; if the HF registry is intended, Dependabot needs it configured or this will churn back on the next in-infra uv lock. cc @Darktex
|
Closing in favor of aggregate env Dependabot PR #1015. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |


Bumps cryptography from 48.0.1 to 50.0.0.
Changelog
Sourced from cryptography's changelog.
... (truncated)
Commits
dcb7050Prepare for 50.0.0 release (#15372)53fccd9Don't leak how PKCS#7 encryptedKey decryption failed (#15369)d472f97Addfrom __future__ import annotationsto all src/ Python files (#15371)908773dBump downstream dependencies in CI (#15368)2cc07ccBump BoringSSL, OpenSSL, AWS-LC in CI (#15367)c94ede9chore(deps): bump ruff from 0.16.0 to 0.16.1 (#15366)67a8308chore(deps): bump virtualenv from 21.7.0 to 21.7.1 (#15365)95018ffRelease the GIL in one-shot AEAD encrypt/decrypt (#15361)6954733Release the GIL during DH and DSA parameter generation (#15364)6893b94Import _serialization instead of serialization in x509/extensions (#15363)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.
Note
Low Risk
Lockfile-only dependency bump for a bench env; main risk is upstream major-version behavior changes in crypto/X.509 if that env exercises those APIs.
Overview
Bumps the locked
cryptographypackage from 48.0.1 to 50.0.0 inenvs/sophistry_bench_sprint_env(viauv.lock). It is pulled in transitively (e.g. through Authlib), not as a direct project dependency.The upgrade is a major release and includes a security fix for PKCS#7
encryptedKeydecryption (CVE-2026-69247), plus stricter X.509/OCSP parsing and other library changes described in the upstream changelog. No application source in this repo is modified—only the environment lockfile.Reviewed by Cursor Bugbot for commit 660ad70. Bugbot is set up for automated code reviews on this repo. Configure here.