Repository navigation
chore(deps-dev): update cryptography requirement from <50.0,>=49.0.0 to >=50.0.0,<51.0 in /agent-governance-python/agent-mesh - #3607
Conversation
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
There was a problem hiding this comment.
Pull request overview
Note
Copilot could not run the full agentic suite for this review because it was automatically requested on a bot-authored pull request. Request a review from Copilot under Reviewers to retry with the full agentic suite. Improved support for bot-authored pull requests is coming soon.
Updates the Python dependency constraints for cryptography in the agent-mesh package.
Changes:
- Bumped
cryptographyfrom>=49.0.0,<50.0to>=50.0.0,<51.0.
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
📦 Dependency diff (SBOM)Comparing main → dependabot/pip/agent-governance-python/agent-mesh/cryptography-gte-50.0.0-and-lt-51.0. ✅ No dependency changes detected. |
2b572bb to
088c6e2
Compare
The core metapackage's <50.0 cap is disjoint with the dependabot dev-extra widens to >=50.0 (#3607/#3610), so their test matrices die at pip install with ResolutionImpossible before a single test runs. Same shape as the 49-cycle widen (#3070). Compatibility evidence for 50.0.0: the full agent-mesh suite passes under cryptography 50 with this cap lifted (3601 passed; the two failures are sandbox-environment subprocess denials, not crypto), on top of the cloud-board/nexus verification from #3588 (85 tests; no applicable 49/50 breaking changes on Ed25519/AESGCM surfaces). Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
|
Dependabot (@dependabot) rebase |
Updates the requirements on [cryptography](https://github.com/pyca/cryptography) to permit the latest version. - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@49.0.0...50.0.0) --- updated-dependencies: - dependency-name: cryptography dependency-version: 50.0.0 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
088c6e2 to
7476170
Compare
…together (#3621) Dependabot raised the two widens separately (#3607/#3610), but docker-compose-test co-installs every package, so each PR conflicts with the other package's still-capped <50.0 dev extra and neither can go green alone. Land both in one change; dependabot closes its PRs automatically once the manifests move. Compatibility evidence for 50.0.0 is already on record: full agent-mesh suite passes under 50 (3601 tests, incl. all 238 crypto-surface tests), cloud-board/nexus verified in the #3588 review, and the core/marketplace runtime caps were widened in #3615/#3604. Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
|
Looks like cryptography is up-to-date now, so this is no longer needed. |
Updates the requirements on cryptography to permit the latest version.
Changelog
Sourced from cryptography's changelog.
... (truncated)
Commits
dcb7050Prepare for 50.0.0 release (#15372)53fccd9Don't leak how PKCS#7 encryptedKey decryption failed (#15369)d472f97Addfrom __future__ import annotationsto all src/ Python files (#15371)908773dBump downstream dependencies in CI (#15368)2cc07ccBump BoringSSL, OpenSSL, AWS-LC in CI (#15367)c94ede9chore(deps): bump ruff from 0.16.0 to 0.16.1 (#15366)67a8308chore(deps): bump virtualenv from 21.7.0 to 21.7.1 (#15365)95018ffRelease the GIL in one-shot AEAD encrypt/decrypt (#15361)6954733Release the GIL during DH and DSA parameter generation (#15364)6893b94Import _serialization instead of serialization in x509/extensions (#15363)