Skip to content

fix(core): widen cryptography upper bound to <51.0 - #3615

Merged
liamcrumm merged 1 commit into
mainfrom
mhabuomar/core-cryptography-51
Aug 4, 2026
Merged

liamcrumm merged 1 commit into
mainfrom
mhabuomar/core-cryptography-51

Conversation

@MohammadHaroonAbuomar

Copy link
Copy Markdown
Collaborator

Summary

The core metapackage caps cryptography<50.0 (pyproject.toml:46) while the open dependabot widens #3607/#3610 move the agent-mesh/agent-os dev extras to >=50.0.0,<51.0. The ranges are disjoint, so those PRs' test matrices fail at pip install with ResolutionImpossible before any test executes. Same fix shape as #3070 (the 49-cycle widen).

Compatibility evidence for cryptography 50.0.0

  • Full agent-mesh suite under 50.0.0 with this cap lifted: 3601 passed, 74 skipped (2 failures were sandbox subprocess denials, unrelated to cryptography) — includes keystore, JWK, X3DH, attestation, CA security, key rotation, Entra verifier, external JWKS (238 crypto-surface tests).
  • cloud-board + nexus verification from the chore(deps): bump cryptography from 48.0.1 to 50.0.0 in /agent-governance-python/agent-os/services/cloud-board #3588 review: 85 tests pass under 50.0.0; none of the 49/50 breaking changes (ChaCha20 nonce semantics, removed aliases, stricter DER/X.509 rejects, FFDH deprecation) touch the used surfaces (Ed25519 raw sign/verify, AESGCM).

Unblock chain

  1. This PR (core cap).
  2. chore(deps): update cryptography requirement from <50.0,>=46.0.7 to >=46.0.7,<51.0 in /agent-governance-python/agent-marketplace #3604 (dependabot, green) widens agent-marketplace — needed by docker-compose-test.
  3. Then @dependabot rebase on chore(deps-dev): update cryptography requirement from <50.0,>=49.0.0 to >=50.0.0,<51.0 in /agent-governance-python/agent-mesh #3607/chore(deps-dev): update cryptography requirement from <50.0,>=49.0.0 to >=50.0.0,<51.0 in /agent-governance-python/agent-os #3610.

Follow-up caps that will bite the same way in future cycles

agent-governance-toolkit-cli mcp extra <49.0; agent-mesh/packages/mcp-trust-server <47.0; agent-os/modules/iatp <50.0; agent-os/modules/nexus <44.0 (stale — nexus itself was verified on 50). Left out of this PR to keep the diff minimal; happy to sweep them in a follow-up if preferred.

The core metapackage's <50.0 cap is disjoint with the dependabot
dev-extra widens to >=50.0 (#3607/#3610), so their test matrices die
at pip install with ResolutionImpossible before a single test runs.
Same shape as the 49-cycle widen (#3070).

Compatibility evidence for 50.0.0: the full agent-mesh suite passes
under cryptography 50 with this cap lifted (3601 passed; the two
failures are sandbox-environment subprocess denials, not crypto), on
top of the cloud-board/nexus verification from #3588 (85 tests; no
applicable 49/50 breaking changes on Ed25519/AESGCM surfaces).

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings August 4, 2026 17:55
@github-actions github-actions Bot added dependencies Pull requests that update a dependency file size/XS Extra small PR (< 10 lines) labels Aug 4, 2026
@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 1 package(s) with unknown licenses.
See the Details below.

License Issues

agent-governance-python/agent-governance-toolkit-core/pyproject.toml

PackageVersionLicenseIssue Type
cryptography>= 46.0.7,< 51.0NullUnknown License
Allowed Licenses: MIT, Apache-2.0, Apache-2.0 WITH LLVM-exception, BSD-2-Clause, BSD-3-Clause, ISC, PSF-2.0, Python-2.0, 0BSD, Unlicense, CC0-1.0, CC-BY-4.0, Zlib, BSL-1.0, MPL-2.0, JSON, Unicode-3.0, CDLA-Permissive-2.0
Excluded from license check: pkg:cargo/futures-timer

OpenSSF Scorecard

PackageVersionScoreDetails
pip/cryptography >= 46.0.7,< 51.0 UnknownUnknown

Scanned Files

  • agent-governance-python/agent-governance-toolkit-core/pyproject.toml

@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown

📦 Dependency diff (SBOM)

Comparing main → mhabuomar/core-cryptography-51.

✅ No dependency changes detected.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Widens the cryptography upper bound in the agent-governance-toolkit-core Python meta-package to avoid dependency-resolution conflicts with related packages that have already moved their dev/test extras to cryptography>=50,<51.

Changes:

  • Update agent-governance-toolkit-core dependency constraint from cryptography<50.0 to cryptography<51.0 to keep ranges compatible with the ongoing 50.x bump cycle.
Show a summary per file
File Description
agent-governance-python/agent-governance-toolkit-core/pyproject.toml Widen cryptography upper bound to <51.0 to prevent disjoint constraints during install/CI resolution.

Review details

  • Files reviewed: 1/1 changed files
  • Comments generated: 0
  • Review effort level: Lite

@liamcrumm
liamcrumm merged commit 4046211 into main Aug 4, 2026
139 checks passed
@liamcrumm
liamcrumm deleted the mhabuomar/core-cryptography-51 branch August 4, 2026 22:42
liamcrumm pushed a commit that referenced this pull request Aug 5, 2026
…together (#3621)

Dependabot raised the two widens separately (#3607/#3610), but
docker-compose-test co-installs every package, so each PR conflicts
with the other package's still-capped <50.0 dev extra and neither can
go green alone. Land both in one change; dependabot closes its PRs
automatically once the manifests move.

Compatibility evidence for 50.0.0 is already on record: full
agent-mesh suite passes under 50 (3601 tests, incl. all 238
crypto-surface tests), cloud-board/nexus verified in the #3588 review,
and the core/marketplace runtime caps were widened in #3615/#3604.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file size/XS Extra small PR (< 10 lines)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants