Skip to content

chore(deps): bump cryptography from 46.0.3 to 46.0.5#456

Closed
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/pip/cryptography-46.0.5
Closed

chore(deps): bump cryptography from 46.0.3 to 46.0.5#456
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/pip/cryptography-46.0.5

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Feb 10, 2026

Bumps cryptography from 46.0.3 to 46.0.5.

Changelog

Sourced from cryptography's changelog.

46.0.5 - 2026-02-10


* An attacker could create a malicious public key that reveals portions of your
  private key when using certain uncommon elliptic curves (binary curves).
  This version now includes additional security checks to prevent this attack.
  This issue only affects binary elliptic curves, which are rarely used in
  real-world applications. Credit to **XlabAI Team of Tencent Xuanwu Lab and
  Atuin Automated Vulnerability Discovery Engine** for reporting the issue.
  **CVE-2026-26007**
* Support for ``SECT*`` binary elliptic curves is deprecated and will be
  removed in the next release.

.. v46-0-4:

46.0.4 - 2026-01-27

  • Dropped support for win_arm64 wheels_.
  • Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.5.5.

.. _v46-0-3:

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [cryptography](https://github.com/pyca/cryptography) from 46.0.3 to 46.0.5.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@46.0.3...46.0.5)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 46.0.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Feb 10, 2026
Copy link

@codecov codecov bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This code review primarily pertains to a single update in the project's requirements.txt file. Most of the requirements remain unchanged, and only the version of the cryptography package was updated. It would be beneficial to understand the rationale behind this version upgrade to ensure compatibility with the existing system and other packages.

cffi==2.0.0 ; python_full_version >= "3.9.2" and platform_python_implementation != "PyPy" and python_version < "4.0"
charset-normalizer==3.4.4 ; python_full_version >= "3.9.2" and python_version < "4.0"
cryptography==46.0.3 ; python_full_version >= "3.9.2" and python_version < "4.0"
cryptography==46.0.5 ; python_full_version >= "3.9.2" and python_version < "4.0"
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The version of the cryptography package has been updated from 46.0.3 to 46.0.5. It's important to ensure this newer version of the package doesn't introduce any breaking changes and is compatible with other dependencies in your project. Additionally, ensure to thoroughly test the application after updating the package to verify that everything still functions as expected.

Copy link

@codecov codecov bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This change simply updates the version of the cryptography package from 46.0.3 to 46.0.5. Overall, there are no major areas of concern now, such as security threats or misuse of library since the change seems harmless as it is only a minor version update. However, it's important to always consider possible implications.

cffi==2.0.0 ; python_full_version >= "3.9.2" and platform_python_implementation != "PyPy" and python_version < "4.0"
charset-normalizer==3.4.4 ; python_full_version >= "3.9.2" and python_version < "4.0"
cryptography==46.0.3 ; python_full_version >= "3.9.2" and python_version < "4.0"
cryptography==46.0.5 ; python_full_version >= "3.9.2" and python_version < "4.0"
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ensure that all dependencies of your project are compatible with this version of 'cryptography'. You should also review the release notes or changelog for 'cryptography==46.0.5' to understand if any breaking changes or new features are introduced that could impact your application.

Copy link

@codecov codecov bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The code change in the Git diff is minimal and largely safe as it only involves updating the version of the cryptography Python package from 46.0.3 to 46.0.5. This should not introduce any breaking changes due to being a minor version increase. However, it could improve security or performance. However, this code review lacks context, so it cannot be determined whether this change is necessary or agrees with the overall project goals and coding standards.

cffi==2.0.0 ; python_full_version >= "3.9.2" and platform_python_implementation != "PyPy" and python_version < "4.0"
charset-normalizer==3.4.4 ; python_full_version >= "3.9.2" and python_version < "4.0"
cryptography==46.0.3 ; python_full_version >= "3.9.2" and python_version < "4.0"
cryptography==46.0.5 ; python_full_version >= "3.9.2" and python_version < "4.0"
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The cryptography package has been updated from version 46.0.3 to 46.0.5. It's generally a good practice to keep libraries updated for improved security and performance. However, it's also necessary to do some integration testing after this update to ensure everything continues to work as expected.

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Feb 11, 2026

Looks like cryptography is up-to-date now, so this is no longer needed.

@dependabot dependabot bot closed this Feb 11, 2026
@dependabot dependabot bot deleted the dependabot/pip/cryptography-46.0.5 branch February 11, 2026 02:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants