Repository navigation
chore(deps): bump cryptography to 50.0.0 in cloud-board with audit trail - #3646
Merged
Merged
Conversation
Supersedes dependabot #3588: the Dependency Audit Trail gate requires the audit doc inside the bumping PR, which dependabot cannot author for majors. Compatibility evidence in the doc; cooling window elapsed 2026-08-07. Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned Files
|
📦 Dependency diff (SBOM)Comparing main → mhabuomar/cloud-board-cryptography-50. ✅ No dependency changes detected. |
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
Contributor
There was a problem hiding this comment.
Pull request overview
TL;DR: 0 blockers, 0 warnings. No issues found. Clean change.
Changes:
- Bump
cryptographypin to50.0.0for the cloud-board service. - Add a dated dependency audit document to satisfy the dependency audit-trail CI gate.
| # | Sev | Issue | Where |
|---|---|---|---|
| 0 | — | No issues found | — |
Show a summary per file
| File | Description |
|---|---|
docs/dependency-audits/2026-08-07-cryptography-50-cloud-board.md |
Adds the required audit-trail documentation for the major bump, including rationale and risk assessment. |
agent-governance-python/agent-os/services/cloud-board/requirements.txt |
Pins cryptography==50.0.0 and points to the corresponding audit doc. |
Review details
- Files reviewed: 2/2 changed files
- Comments generated: 0
- Review effort level: Lite
Resolve requirements.txt conflict: both sides pin cryptography==50.0.0; keep the PR's comment that references the dependency audit doc. Signed-off-by: Prayag Upadhyay <prayag.upd@gmail.com>
requirements.txt pins cryptography==50.0.0 but requirements.lock still pinned 46.0.5. Bump the lock entry to 50.0.0 with the full set of 46 upstream PyPI sha256 hashes (verified against the /pypi/cryptography/ 50.0.0/json artifact digests). Addresses the review note that the lock lagged the requirement. Signed-off-by: Prayag Upadhyay <prayag.upd@gmail.com>
The cryptography 50.0.0 audit doc introduces standard crypto vocabulary (AESGCM, Bleichenbacher, FFDH, OCSP, SPKI) that cspell's bundled dictionaries do not recognize, failing the Spell-check job. Add them to the repo terms allowlist so the audit doc passes deterministically. Signed-off-by: Prayag Upadhyay <prayag.upd@gmail.com>
Prayag (prayagupa)
approved these changes
Aug 12, 2026
liamcrumm
approved these changes
Aug 12, 2026
17 of 47 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Related Issue
Supersedes dependabot #3588 (dependabot auto-closes it when this merges).
Problem & Solution
Problem: the cloud-board cryptography 48->50 major bump is fully verified and past its cooling window, but the Dependency Audit Trail gate requires a maintainer-authored audit doc inside the bumping PR, which dependabot cannot provide, and the repo policy now avoids pushing commits onto dependabot branches.
Solution: this PR carries the identical one-line bump plus the required
docs/dependency-audits/2026-08-07-cryptography-50-cloud-board.md, and refreshes the stale CVE comment on the pin line.Impact on Your Work
Unblocks the last cooling-gated dependabot major and completes the repo-wide cryptography-50 move (caps widened in #3615/#3621; marketplace pin #3622 merges via the routine flow).
Timeline
None.
Alternatives Considered
Pushing the doc to dependabot's #3588 branch (rejected by the no-pushes-to-contributor-branches policy); relaxing the audit-trail gate for majors (worse control).
Type of Change
Verification
Note: the
Validate docs frontmattercheck will show the known pre-existing failure ondocs/security/audits/2026-07-31-fail-open-closure-python-reference.mduntil #3619 or #3523 merges — unrelated to this diff.