Skip to content

chore(deps): bump cryptography from 46.0.5 to 46.0.6#8072

Merged
leandrodamascena merged 2 commits intodevelopfrom
dependabot/pip/cryptography-46.0.6
Apr 2, 2026
Merged

chore(deps): bump cryptography from 46.0.5 to 46.0.6#8072
leandrodamascena merged 2 commits intodevelopfrom
dependabot/pip/cryptography-46.0.6

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Mar 29, 2026

Bumps cryptography from 46.0.5 to 46.0.6.

Changelog

Sourced from cryptography's changelog.

46.0.6 - 2026-03-25


* **SECURITY ISSUE**: Fixed a bug where name constraints were not applied
  to peer names during verification when the leaf certificate contains a
  wildcard DNS SAN. Ordinary X.509 topologies are not affected by this bug,
  including those used by the Web PKI. Credit to **Oleh Konko (1seal)** for
  reporting the issue. **CVE-2026-34073**

.. _v46-0-5:

Commits

@dependabot dependabot bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Mar 29, 2026
@dependabot dependabot bot requested a review from a team as a code owner March 29, 2026 00:38
@dependabot dependabot bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Mar 29, 2026
@dependabot dependabot bot requested a review from leandrodamascena March 29, 2026 00:38
@pull-request-size pull-request-size bot added the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Mar 29, 2026
@dependabot dependabot bot force-pushed the dependabot/pip/cryptography-46.0.6 branch 2 times, most recently from e98504c to 8c185c7 Compare April 2, 2026 10:17
Bumps [cryptography](https://github.com/pyca/cryptography) from 46.0.5 to 46.0.6.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@46.0.5...46.0.6)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 46.0.6
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/pip/cryptography-46.0.6 branch from 8c185c7 to 937961a Compare April 2, 2026 10:19
@powertools-for-aws-oss-automation powertools-for-aws-oss-automation bot added size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. and removed size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. labels Apr 2, 2026
@sonarqubecloud
Copy link
Copy Markdown

sonarqubecloud bot commented Apr 2, 2026

@leandrodamascena leandrodamascena merged commit a03daf5 into develop Apr 2, 2026
16 checks passed
@leandrodamascena leandrodamascena deleted the dependabot/pip/cryptography-46.0.6 branch April 2, 2026 10:39
@codecov
Copy link
Copy Markdown

codecov bot commented Apr 2, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 96.64%. Comparing base (78f9cdf) to head (1f71156).
⚠️ Report is 5 commits behind head on develop.

Additional details and impacted files
@@           Coverage Diff            @@
##           develop    #8072   +/-   ##
========================================
  Coverage    96.64%   96.64%           
========================================
  Files          282      282           
  Lines        13790    13790           
  Branches      1102     1102           
========================================
  Hits         13328    13328           
  Misses         339      339           
  Partials       123      123           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code size/XS Denotes a PR that changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant