Skip to content

chore(deps): bump cryptography from 46.0.7 to 48.0.1 in /agent-governance-python/agent-os/services/cloud-board - #3036

Merged
MohammadHaroonAbuomar merged 3 commits into
mainfrom
dependabot/pip/agent-governance-python/agent-os/services/cloud-board/cryptography-48.0.1
Jun 23, 2026
Merged

MohammadHaroonAbuomar merged 3 commits into
mainfrom
dependabot/pip/agent-governance-python/agent-os/services/cloud-board/cryptography-48.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 15, 2026 •

Copy link
Copy Markdown
Contributor

Bumps cryptography from 46.0.7 to 48.0.1.

Changelog

Sourced from cryptography's changelog.

48.0.1 - 2026-06-09


* Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.1.

.. _v48-0-0:

48.0.0 - 2026-05-04

  • BACKWARDS INCOMPATIBLE: Support for Python 3.8 has been removed. cryptography now requires Python 3.9 or later.

  • BACKWARDS INCOMPATIBLE: Loading an X.509 CRL whose inner TBSCertList.signature algorithm does not match the outer signatureAlgorithm now raises ValueError. Previously, such CRLs were parsed successfully and only rejected during signature validation.

  • Added support for :doc:/hazmat/primitives/asymmetric/mlkem and :doc:/hazmat/primitives/asymmetric/mldsa when using OpenSSL 3.5.0 or later, in addition to the existing AWS-LC and BoringSSL support. This means post-quantum algorithms are now available to users of our wheels.

    • Note: Going forward, we do not guarantee that all functionality in cryptography will be available when building against OpenSSL. See :doc:/statements/state-of-openssl for more information.

.. _v47-0-0:

47.0.0 - 2026-04-24


* Support for Python 3.8 is deprecated and will be removed in the next
  ``cryptography`` release.
* **BACKWARDS INCOMPATIBLE:** Support for binary elliptic curves
  (``SECT*`` classes) has been removed. These curves are rarely used and
  have additional security considerations that make them undesirable.
* **BACKWARDS INCOMPATIBLE:** Support for OpenSSL 1.1.x has been removed.
  OpenSSL 3.0.0 or later is now required. LibreSSL, BoringSSL, and AWS-LC
  continue to be supported.
* **BACKWARDS INCOMPATIBLE:** Dropped support for LibreSSL < 4.1.
* **BACKWARDS INCOMPATIBLE:** Loading keys with unsupported algorithms or
  keys with unsupported explicit curve encodings now raises
  :class:`~cryptography.exceptions.UnsupportedAlgorithm` instead of
  ``ValueError``. This change affects
  :func:`~cryptography.hazmat.primitives.serialization.load_pem_private_key`,
  :func:`~cryptography.hazmat.primitives.serialization.load_der_private_key`,
  :func:`~cryptography.hazmat.primitives.serialization.load_pem_public_key`,
  :func:`~cryptography.hazmat.primitives.serialization.load_der_public_key`,
  and :meth:`~cryptography.x509.Certificate.public_key` when called on
  certificates with unsupported public key algorithms.
</tr></table> 

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Jun 15, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Jun 15, 2026
@github-actions

github-actions Bot commented Jun 15, 2026 •

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

@github-actions

github-actions Bot commented Jun 15, 2026 •

Copy link
Copy Markdown

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 1 package(s) with unknown licenses.
See the Details below.

License Issues

agent-governance-python/agent-os/services/cloud-board/requirements.txt

PackageVersionLicenseIssue Type
cryptography48.0.1NullUnknown License
Allowed Licenses: MIT, Apache-2.0, Apache-2.0 WITH LLVM-exception, BSD-2-Clause, BSD-3-Clause, ISC, PSF-2.0, Python-2.0, 0BSD, Unlicense, CC0-1.0, CC-BY-4.0, Zlib, BSL-1.0, MPL-2.0, JSON, Unicode-3.0, CDLA-Permissive-2.0
Excluded from license check: pkg:cargo/futures-timer

OpenSSF Scorecard

PackageVersionScoreDetails
pip/cryptography 48.0.1 UnknownUnknown

Scanned Files

  • agent-governance-python/agent-os/services/cloud-board/requirements.txt

@github-actions github-actions Bot added the size/XS Extra small PR (< 10 lines) label Jun 15, 2026
@github-actions

github-actions Bot commented Jun 15, 2026 •

Copy link
Copy Markdown

📦 Dependency diff (SBOM)

Comparing main → dependabot/pip/agent-governance-python/agent-os/services/cloud-board/cryptography-48.0.1.

✅ No dependency changes detected.

@imran-siddique

Copy link
Copy Markdown
Collaborator

Two things blocking this:

  1. 7-day cooling-off: this is a direct production dependency bump (requirements.txt pin), so the cooling-off gate applies. It will clear automatically on 2026-06-22.

  2. Test failure: test_flat_yaml_match_isolated_from_top_level_mutation is failing because this branch is behind the deepcopy fix that landed in fix(agent-os): deepcopy context in YAML-match audit entry #3037. Run @dependabot rebase to pull that in — the test passes on current main.

Bumps [cryptography](https://github.com/pyca/cryptography) from 46.0.7 to 48.0.1.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@46.0.7...48.0.1)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 48.0.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/agent-governance-python/agent-os/services/cloud-board/cryptography-48.0.1 branch from a1a459b to 603477c Compare June 16, 2026 20:30
@github-actions github-actions Bot added documentation Improvements or additions to documentation size/S Small PR (< 50 lines) and removed size/XS Extra small PR (< 10 lines) labels Jun 17, 2026
@github-actions

github-actions Bot commented Jun 17, 2026 •

Copy link
Copy Markdown
🤖 AI Agent: test-generator — View details

AI-generated review output. Treat it as untrusted analysis and verify before acting.

Test coverage looks good. No gaps identified.

@github-actions

github-actions Bot commented Jun 17, 2026 •

Copy link
Copy Markdown
🤖 AI Agent: docs-sync-checker — Docs Sync

AI-generated review output. Treat it as untrusted analysis and verify before acting.

Docs Sync

Documentation is in sync.

@github-actions

github-actions Bot commented Jun 17, 2026 •

Copy link
Copy Markdown
🤖 AI Agent: breaking-change-detector — API Compatibility

AI-generated review output. Treat it as untrusted analysis and verify before acting.

API Compatibility

Severity Change Impact
High Dropped support for Python 3.8. Cryptography now requires Python 3.9 or later. Users running the application with Python 3.8 will encounter compatibility issues.
High Dropped support for OpenSSL 1.1.x. OpenSSL 3.0.0 or later is now required. Systems using OpenSSL 1.1.x will fail to function with the updated library.
High Dropped support for LibreSSL versions earlier than 4.1. Systems using older versions of LibreSSL will no longer be supported.
High Removed support for binary elliptic curves (SECT* classes). Applications relying on these curves will encounter errors.
Medium Loading an X.509 CRL with mismatched TBSCertList.signature and signatureAlgorithm now raises ValueError. May cause runtime errors in applications that previously handled such CRLs without issue.
Medium Loading keys with unsupported algorithms or explicit curve encodings now raises UnsupportedAlgorithm instead of ValueError. Applications relying on the previous behavior will need to handle the new exception type.

@github-actions

github-actions Bot commented Jun 17, 2026 •

Copy link
Copy Markdown
🤖 AI Agent: security-scanner — View details

AI-generated review output. Treat it as untrusted analysis and verify before acting.

No security issues found.

@github-actions

github-actions Bot commented Jun 17, 2026 •

Copy link
Copy Markdown
🤖 AI Agent: code-reviewer — View details

AI-generated review output. Treat it as untrusted analysis and verify before acting.

TL;DR: 1 blocker, 0 warnings. Breaking changes in the cryptography library require further review.

# Sev Issue Where
1 Blocker cryptography 48.x introduces breaking changes, including Python 3.8 deprecation and stricter X.509 CRL parsing. requirements.txt update

Action items:

  1. Verify compatibility of the agent-os cloud-board service with cryptography 48.x, especially regarding Python version requirements and stricter X.509 CRL parsing.

No warnings.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cryptography 48.0.1 security bump: dep audit trail present, cooling-off cleared, all tests green. Approving.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Bumps cryptography 46.0.7 -> 48.0.1 in cloud-board service to address GHSA CVEs. Dependency audit doc present. Will auto-merge once 7-day cooling-off clears (2026-06-22).

@imran-siddique

Copy link
Copy Markdown
Collaborator

The DCO failure here is a known dependabot limitation: the bot does not add Signed-off-by to its commits. All other CI gates pass including the 7-day cooling-off, and the cryptography bump from 46.0.7 to 48.0.1 is legitimate (OpenSSL 4.0.1 wheel update, Python 3.8 EOL drop, post-quantum ML-KEM/ML-DSA support). Code has already been approved.

To unblock: the repo needs a .github/dco.yml with a allowRemediatedCommits: true entry or a bot-exemption for dependabot[bot]. Until that is in place this PR cannot merge through CI.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The dependency bump itself (cryptography 46.0.7 → 48.0.1) is warranted and the requirements.txt change in commit 603477c5 is correct with its SOB.

Blocker: DCO failure on c73773c8 -- the audit-doc commit is missing Signed-off-by. Please amend it:

git commit --amend --signoff
git push --force-with-lease

The DCO check will pass once that commit carries the Signed-off-by: <author> <email> line.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The 7-day cooling-off has passed (opened June 15). All automated CI checks pass except DCO.

The DCO failure is for commit c73773c8 docs(audit): add dependency audit for cryptography 48.0.1 in cloud-board authored by Imran Siddique -- not the dependabot commit itself. Please amend that commit to add a Signed-off-by trailer (git commit --amend --signoff) and force-push, then I can approve.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
@imran-siddique
Imran Siddique (imran-siddique) force-pushed the dependabot/pip/agent-governance-python/agent-os/services/cloud-board/cryptography-48.0.1 branch from c73773c to cabcd66 Compare June 22, 2026 19:55
…-os/services/cloud-board/cryptography-48.0.1

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DCO is now resolved (commit amended with Signed-off-by in the previous fix pass). Cooling-off cleared 2026-06-22. All required checks pass. Approving to supersede the stale CHANGES_REQUESTED.

@MohammadHaroonAbuomar MohammadHaroonAbuomar left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Routine dependency bump — reviewed in batch.

@MohammadHaroonAbuomar
MohammadHaroonAbuomar merged commit 73c8aec into main Jun 23, 2026
135 checks passed
@MohammadHaroonAbuomar
MohammadHaroonAbuomar deleted the dependabot/pip/agent-governance-python/agent-os/services/cloud-board/cryptography-48.0.1 branch June 23, 2026 19:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file documentation Improvements or additions to documentation python Pull requests that update python code size/S Small PR (< 50 lines)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants