Skip to content

chore(deps): bump cryptography from 46.0.6 to 46.0.7 in the cryptography group across 1 directory#8900

Open
dependabot[bot] wants to merge 1 commit intodevelopfrom
dependabot/pip/develop/cryptography-3344959f9f
Open

chore(deps): bump cryptography from 46.0.6 to 46.0.7 in the cryptography group across 1 directory#8900
dependabot[bot] wants to merge 1 commit intodevelopfrom
dependabot/pip/develop/cryptography-3344959f9f

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Apr 8, 2026

Bumps the cryptography group with 1 update in the / directory: cryptography.

Updates cryptography from 46.0.6 to 46.0.7

Changelog

Sourced from cryptography's changelog.

46.0.7 - 2026-04-07


* **SECURITY ISSUE**: Fixed an issue where non-contiguous buffers could be
  passed to APIs that accept Python buffers, which could lead to buffer
  overflow. **CVE-2026-39892**
* Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.5.6.

.. _v46-0-6:

Commits

@dependabot dependabot bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Apr 8, 2026
@dependabot dependabot bot requested a review from a team as a code owner April 8, 2026 08:18
@dependabot dependabot bot added python Pull requests that update Python code dependencies Pull requests that update a dependency file labels Apr 8, 2026
@dependabot dependabot bot changed the title chore(deps): bump cryptography from 46.0.6 to 46.0.7 in the cryptography group chore(deps): bump cryptography from 46.0.6 to 46.0.7 in the cryptography group across 1 directory Apr 9, 2026
@dependabot dependabot bot force-pushed the dependabot/pip/develop/cryptography-3344959f9f branch 3 times, most recently from df2a389 to f82c246 Compare April 13, 2026 08:26
@dependabot dependabot bot force-pushed the dependabot/pip/develop/cryptography-3344959f9f branch from f82c246 to a495c00 Compare April 16, 2026 08:15
Copy link
Copy Markdown
Contributor

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This review has been superseded by a newer review.

Bumps the cryptography group with 1 update: [cryptography](https://github.com/pyca/cryptography).


Updates `cryptography` from 46.0.6 to 46.0.7
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@46.0.6...46.0.7)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 46.0.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: cryptography
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/pip/develop/cryptography-3344959f9f branch from a495c00 to 2b47933 Compare April 17, 2026 08:14
Copy link
Copy Markdown
Contributor

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review Results

Reviewed: 09c3cd5..2b47933
Files: 3
Comments: 0

✅ No issues found. The changes look good.

This is a clean patch version bump of cryptography from 46.0.6 to 46.0.7 across all three platform-specific reproducible requirements files (linux, mac, win). The hashes are consistent across all three files, the # via pyopenssl provenance comment is preserved, and no other dependencies are affected.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file pr/internal python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant