Skip to content

build(deps): bump cryptography from 46.0.6 to 46.0.7#1777

Closed
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/uv/cryptography-46.0.7
Closed

build(deps): bump cryptography from 46.0.6 to 46.0.7#1777
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/uv/cryptography-46.0.7

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 8, 2026

Bumps cryptography from 46.0.6 to 46.0.7.

Changelog

Sourced from cryptography's changelog.

46.0.7 - 2026-04-07


* **SECURITY ISSUE**: Fixed an issue where non-contiguous buffers could be
  passed to APIs that accept Python buffers, which could lead to buffer
  overflow. **CVE-2026-39892**
* Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.5.6.

.. _v46-0-6:

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Apr 8, 2026
@dependabot dependabot Bot requested a review from a team as a code owner April 8, 2026 23:00
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Apr 8, 2026
@copy-pr-bot
Copy link
Copy Markdown

copy-pr-bot Bot commented Apr 8, 2026

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@dependabot dependabot Bot force-pushed the dependabot/uv/cryptography-46.0.7 branch 2 times, most recently from 63aa12f to ab574f2 Compare April 10, 2026 19:03
@dependabot dependabot Bot changed the title chore(deps): bump cryptography from 46.0.6 to 46.0.7 build(deps): bump cryptography from 46.0.6 to 46.0.7 Apr 14, 2026
@dependabot dependabot Bot force-pushed the dependabot/uv/cryptography-46.0.7 branch 3 times, most recently from 1f791b0 to fdd1d4d Compare April 14, 2026 23:15
@dependabot dependabot Bot force-pushed the dependabot/uv/cryptography-46.0.7 branch 2 times, most recently from 8a52d08 to 6d7412e Compare April 22, 2026 14:53
Bumps [cryptography](https://github.com/pyca/cryptography) from 46.0.6 to 46.0.7.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@46.0.6...46.0.7)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 46.0.7
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/uv/cryptography-46.0.7 branch from 6d7412e to 1bc93e1 Compare April 24, 2026 05:47
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Apr 24, 2026

Looks like cryptography is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Apr 24, 2026
@dependabot dependabot Bot deleted the dependabot/uv/cryptography-46.0.7 branch April 24, 2026 23:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants