Skip to content

deps(security): cryptography >= 46.0.7 (GHSA-p423-j2cm-9vmq)#227

Merged
neuron7xLab merged 1 commit intomainfrom
security/cryptography-46.0.7
Apr 13, 2026
Merged

deps(security): cryptography >= 46.0.7 (GHSA-p423-j2cm-9vmq)#227
neuron7xLab merged 1 commit intomainfrom
security/cryptography-46.0.7

Conversation

@neuron7xLab
Copy link
Copy Markdown
Owner

Summary

Closes the single open Dependabot advisory on main:

  • GHSA-p423-j2cm-9vmq (moderate) — Cryptography buffer overflow with non-contiguous buffers. Vulnerable >= 45.0.0, < 46.0.7; current pin 46.0.6; fix in 46.0.7+.

Changes

Bumps floor in the three source-of-truth manifests + regenerated SBOM row:

  • `pyproject.toml`
  • `requirements.txt`
  • `requirements-scan.txt`
  • `sbom/combined-requirements.txt` (pin updated to match)

Risk

Minor point-release. No API change on cipher/hash/x509 paths we use.

Test plan

  • CI green (python-quality + fast/heavy tests)
  • Dependabot rescan closes GHSA-p423-j2cm-9vmq on merge

🤖 Generated with Claude Code

Closes the single open Dependabot advisory on GeoSync main:

  GHSA-p423-j2cm-9vmq — Cryptography buffer-overflow with
  non-contiguous buffers (moderate). Vulnerable range
  ``>= 45.0.0, < 46.0.7``; current pin 46.0.6; fix 46.0.7+.

Bumps the floor in the three source-of-truth manifests
(``pyproject.toml``, ``requirements.txt``, ``requirements-scan.txt``)
and the generated ``sbom/combined-requirements.txt`` together so the
SBOM stays consistent with the lockfiles.

Minor point-release of a widely-deployed library — no API change
on the code paths we use (cipher/hash/x509 primitives).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@chatgpt-codex-connector
Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@neuron7xLab neuron7xLab merged commit 3cf2010 into main Apr 13, 2026
10 checks passed
@neuron7xLab neuron7xLab deleted the security/cryptography-46.0.7 branch April 13, 2026 21:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant