chore(deps): Bump cryptography from 48.0.0 to 49.0.0#388
chore(deps): Bump cryptography from 48.0.0 to 49.0.0#388dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [cryptography](https://github.com/pyca/cryptography) from 48.0.0 to 49.0.0. - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@48.0.0...49.0.0) --- updated-dependencies: - dependency-name: cryptography dependency-version: 49.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Changes Reviewedrequirements.txt, requirements-dev.txt (full review) Code Review🐛 Bugs & CorrectnessNo issues found. 🔒 SecurityNo issues found. ⚡ PerformanceNo issues found. 🏗️ Code QualityNo issues found. ✅ Tests & DocumentationNo issues found. Actionable SuggestionsNone — this is a straightforward dependency update from cryptography 48.0.0 to 49.0.0. Overall AssessmentLGTM ✅ Reviewed by MedCover Reviewer AI · Full review |
Changes Reviewedrequirements-dev.txt, requirements.txt — Dependency bump for cryptography from 48.0.0 to 49.0.0 (hash update only). Code Review🐛 Bugs & CorrectnessNo issues found. 🔒 SecurityNo issues found. This is a minor version bump for a cryptography library, which may include security patches. ⚡ PerformanceNo issues found. 🏗️ Code QualityNo issues found. ✅ Tests & DocumentationNo issues found. Actionable SuggestionsNone. Overall AssessmentLGTM ✅ Straightforward dependency update with proper hash verification. Reviewed by MedCover Reviewer AI · Full review |
Bumps cryptography from 48.0.0 to 49.0.0.
Changelog
Sourced from cryptography's changelog.
... (truncated)
Commits
e300bbebump version and changelog for 49.0.0 (#15030)fa74cd8Add external mu (message representative) support for ML-DSA (#14979)f594db3chore(deps): bump openssl from 0.10.80 to 0.10.81 (#15029)608e011chore(deps): bump openssl-sys from 0.9.116 to 0.9.117 (#15028)a322bc4chore(deps): bump cc from 1.2.63 to 1.2.64 (#15027)33181a7Reject critical nameConstraints extensions containing directoryName constrain...6080dc7Bump dependencies that dependabot isn't (#15026)121faa3chore(deps): bump virtualenv from 21.4.2 to 21.4.3 (#15023)829520bAdd more robust processing for DH parameters. (#15016)0f05001Bump downstream dependencies in CI (#15025)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)