Repository navigation
Conversation
Updates the requirements on [cryptography](https://github.com/pyca/cryptography) to permit the latest version. - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@46.0.7...50.0.0) --- updated-dependencies: - dependency-name: cryptography dependency-version: 50.0.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
There was a problem hiding this comment.
Pull request overview
Note
Copilot could not run the full agentic suite for this review because it was automatically requested on a bot-authored pull request. Request a review from Copilot under Reviewers to retry with the full agentic suite. Improved support for bot-authored pull requests is coming soon.
Updates the Python dependency constraints for agent-marketplace to allow newer cryptography versions.
Changes:
- Relaxed the upper bound on
cryptographyfrom<50.0to<51.0.
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
Dependency ReviewThe following issues were found:
License Issuesagent-governance-python/agent-marketplace/pyproject.toml
OpenSSF Scorecard
Scanned Files
|
📦 Dependency diff (SBOM)Comparing main → dependabot/pip/agent-governance-python/agent-marketplace/cryptography-gte-46.0.7-and-lt-51.0. ✅ No dependency changes detected. |
…-marketplace/cryptography-gte-46.0.7-and-lt-51.0
There was a problem hiding this comment.
Review details
Suppressed comments (1)
agent-governance-python/agent-marketplace/pyproject.toml:32
- This range now permits
cryptography==50.0.0, which the PR description indicates was released on 2026-07-31 (less than 7 days before the current date in this PR). To follow the repo’s supply-chain stability guidance, consider temporarily excluding 50.0.0 while still widening the upper bound.
"cryptography>=46.0.7,<51.0",
- Files reviewed: 1/1 changed files
- Comments generated: 0 new
- Review effort level: Lite
…together (#3621) Dependabot raised the two widens separately (#3607/#3610), but docker-compose-test co-installs every package, so each PR conflicts with the other package's still-capped <50.0 dev extra and neither can go green alone. Land both in one change; dependabot closes its PRs automatically once the manifests move. Compatibility evidence for 50.0.0 is already on record: full agent-mesh suite passes under 50 (3601 tests, incl. all 238 crypto-surface tests), cloud-board/nexus verified in the #3588 review, and the core/marketplace runtime caps were widened in #3615/#3604. Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
Updates the requirements on cryptography to permit the latest version.
Changelog
Sourced from cryptography's changelog.
... (truncated)
Commits
dcb7050Prepare for 50.0.0 release (#15372)53fccd9Don't leak how PKCS#7 encryptedKey decryption failed (#15369)d472f97Addfrom __future__ import annotationsto all src/ Python files (#15371)908773dBump downstream dependencies in CI (#15368)2cc07ccBump BoringSSL, OpenSSL, AWS-LC in CI (#15367)c94ede9chore(deps): bump ruff from 0.16.0 to 0.16.1 (#15366)67a8308chore(deps): bump virtualenv from 21.7.0 to 21.7.1 (#15365)95018ffRelease the GIL in one-shot AEAD encrypt/decrypt (#15361)6954733Release the GIL during DH and DSA parameter generation (#15364)6893b94Import _serialization instead of serialization in x509/extensions (#15363)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)