Skip to content

chore(deps): bump cryptography to 50.0.0 in cloud-board with audit trail - #3646

Merged
liamcrumm merged 5 commits into
mainfrom
mhabuomar/cloud-board-cryptography-50
Aug 12, 2026
Merged

liamcrumm merged 5 commits into
mainfrom
mhabuomar/cloud-board-cryptography-50

Conversation

@MohammadHaroonAbuomar

Copy link
Copy Markdown
Collaborator

Related Issue

Supersedes dependabot #3588 (dependabot auto-closes it when this merges).

Problem & Solution

Problem: the cloud-board cryptography 48->50 major bump is fully verified and past its cooling window, but the Dependency Audit Trail gate requires a maintainer-authored audit doc inside the bumping PR, which dependabot cannot provide, and the repo policy now avoids pushing commits onto dependabot branches.
Solution: this PR carries the identical one-line bump plus the required docs/dependency-audits/2026-08-07-cryptography-50-cloud-board.md, and refreshes the stale CVE comment on the pin line.

Impact on Your Work

Unblocks the last cooling-gated dependabot major and completes the repo-wide cryptography-50 move (caps widened in #3615/#3621; marketplace pin #3622 merges via the routine flow).

Timeline

None.

Alternatives Considered

Pushing the doc to dependabot's #3588 branch (rejected by the no-pushes-to-contributor-branches policy); relaxing the audit-trail gate for majors (worse control).

Type of Change

  • Dependency update with audit trail

Verification

Note: the Validate docs frontmatter check will show the known pre-existing failure on docs/security/audits/2026-07-31-fail-open-closure-python-reference.md until #3619 or #3523 merges — unrelated to this diff.

Supersedes dependabot #3588: the Dependency Audit Trail gate requires
the audit doc inside the bumping PR, which dependabot cannot author
for majors. Compatibility evidence in the doc; cooling window elapsed
2026-08-07.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings August 7, 2026 14:25
@github-actions github-actions Bot added documentation Improvements or additions to documentation dependencies Pull requests that update a dependency file labels Aug 7, 2026
@github-actions

github-actions Bot commented Aug 7, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

  • agent-governance-python/agent-os/services/cloud-board/requirements.txt

@github-actions

github-actions Bot commented Aug 7, 2026

Copy link
Copy Markdown

📦 Dependency diff (SBOM)

Comparing main → mhabuomar/cloud-board-cryptography-50.

✅ No dependency changes detected.

@github-actions

github-actions Bot commented Aug 7, 2026

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

TL;DR: 0 blockers, 0 warnings. No issues found. Clean change.

Changes:

  • Bump cryptography pin to 50.0.0 for the cloud-board service.
  • Add a dated dependency audit document to satisfy the dependency audit-trail CI gate.
# Sev Issue Where
0 — No issues found —
Show a summary per file
File Description
docs/dependency-audits/2026-08-07-cryptography-50-cloud-board.md Adds the required audit-trail documentation for the major bump, including rationale and risk assessment.
agent-governance-python/agent-os/services/cloud-board/requirements.txt Pins cryptography==50.0.0 and points to the corresponding audit doc.

Review details

  • Files reviewed: 2/2 changed files
  • Comments generated: 0
  • Review effort level: Lite

Resolve requirements.txt conflict: both sides pin cryptography==50.0.0;
keep the PR's comment that references the dependency audit doc.

Signed-off-by: Prayag Upadhyay <prayag.upd@gmail.com>
requirements.txt pins cryptography==50.0.0 but requirements.lock still
pinned 46.0.5. Bump the lock entry to 50.0.0 with the full set of 46
upstream PyPI sha256 hashes (verified against the /pypi/cryptography/
50.0.0/json artifact digests). Addresses the review note that the lock
lagged the requirement.

Signed-off-by: Prayag Upadhyay <prayag.upd@gmail.com>
@github-actions github-actions Bot added size/M Medium PR (< 200 lines) and removed size/S Small PR (< 50 lines) labels Aug 12, 2026
The cryptography 50.0.0 audit doc introduces standard crypto vocabulary
(AESGCM, Bleichenbacher, FFDH, OCSP, SPKI) that cspell's bundled
dictionaries do not recognize, failing the Spell-check job. Add them to
the repo terms allowlist so the audit doc passes deterministically.

Signed-off-by: Prayag Upadhyay <prayag.upd@gmail.com>
@liamcrumm
liamcrumm merged commit 7d0cef5 into main Aug 12, 2026
136 checks passed
@liamcrumm
liamcrumm deleted the mhabuomar/cloud-board-cryptography-50 branch August 12, 2026 22:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file documentation Improvements or additions to documentation size/M Medium PR (< 200 lines)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants