Skip to content

build(deps): bump cryptography from 46.0.6 to 46.0.7 in /jobs/async-upload#2560

Merged
google-oss-prow[bot] merged 2 commits intomainfrom
dependabot/pip/jobs/async-upload/cryptography-46.0.7
Apr 9, 2026
Merged

build(deps): bump cryptography from 46.0.6 to 46.0.7 in /jobs/async-upload#2560
google-oss-prow[bot] merged 2 commits intomainfrom
dependabot/pip/jobs/async-upload/cryptography-46.0.7

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Apr 8, 2026

Bumps cryptography from 46.0.6 to 46.0.7.

Changelog

Sourced from cryptography's changelog.

46.0.7 - 2026-04-07


* **SECURITY ISSUE**: Fixed an issue where non-contiguous buffers could be
  passed to APIs that accept Python buffers, which could lead to buffer
  overflow. **CVE-2026-39892**
* Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.5.6.

.. _v46-0-6:

Commits

@dependabot dependabot bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Apr 8, 2026
@google-oss-prow google-oss-prow bot requested review from chambridge and fege April 8, 2026 21:46
Bumps [cryptography](https://github.com/pyca/cryptography) from 46.0.6 to 46.0.7.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@46.0.6...46.0.7)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 46.0.7
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/pip/jobs/async-upload/cryptography-46.0.7 branch from 0d494d3 to 59be426 Compare April 9, 2026 13:44
Signed-off-by: Jon Burdo <jon@jonburdo.com>
@jonburdo
Copy link
Copy Markdown
Member

jonburdo commented Apr 9, 2026

cryptography is a transitive dependency through model-registry[signing] used for signing models

a micro/patch version bump

$ poetry show cryptography
 name         : cryptography                                                                                        
 version      : 46.0.7                                                                                              
 description  : cryptography is a package which provides cryptographic recipes and primitives to Python developers. 

dependencies
 - cffi >=2.0.0

required by
 - pyopenssl requires >=46.0.0,<47
 - rfc3161-client requires >=43,<47
 - rh-model-signing requires *
 - sigstore requires >=42,<47

/lgtm
/approve

@google-oss-prow
Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: jonburdo

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@google-oss-prow google-oss-prow bot merged commit 5854e61 into main Apr 9, 2026
35 of 36 checks passed
@dependabot dependabot bot deleted the dependabot/pip/jobs/async-upload/cryptography-46.0.7 branch April 9, 2026 14:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Area/Jobs/Async-upload dependencies Pull requests that update a dependency file lgtm python Pull requests that update Python code size/L

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant