Skip to content

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Sep 17, 2025

Bumps cryptography from 45.0.7 to 46.0.1.

Changelog

Sourced from cryptography's changelog.

46.0.1 - 2025-09-16


* Fixed an issue where users installing via ``pip`` on Python 3.14 development
  versions would not properly install a dependency.
* Fixed an issue building the free-threaded macOS 3.14 wheels.

.. _v46-0-0:

46.0.0 - 2025-09-16

  • BACKWARDS INCOMPATIBLE: Support for Python 3.7 has been removed.
  • Support for OpenSSL < 3.0 is deprecated and will be removed in the next release.
  • Support for x86_64 macOS (including publishing wheels) is deprecated and will be removed in two releases. We will switch to publishing an arm64 only wheel for macOS.
  • Support for 32-bit Windows (including publishing wheels) is deprecated and will be removed in two releases. Users should move to a 64-bit Python installation.
  • Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.5.3.
  • We now build ppc64le manylinux wheels and publish them to PyPI.
  • We now build win_arm64 (Windows on Arm) wheels and publish them to PyPI.
  • Added support for free-threaded Python 3.14.
  • Removed the deprecated get_attribute_for_oid method on :class:~cryptography.x509.CertificateSigningRequest. Users should use :meth:~cryptography.x509.Attributes.get_attribute_for_oid instead.
  • Removed the deprecated CAST5, SEED, IDEA, and Blowfish classes from the cipher module. These are still available in :doc:/hazmat/decrepit/index.
  • In X.509, when performing a PSS signature with a SHA-3 hash, it is now encoded with the official NIST SHA3 OID.

.. _v45-0-7:

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [cryptography](https://github.com/pyca/cryptography) from 45.0.7 to 46.0.1.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@45.0.7...46.0.1)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 46.0.1
  dependency-type: indirect
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Sep 17, 2025
@github-actions github-actions bot enabled auto-merge (squash) September 17, 2025 10:12
Copy link

codspeed-hq bot commented Sep 17, 2025

CodSpeed Performance Report

Merging #11515 will not alter performance

Comparing dependabot/pip/cryptography-46.0.1 (83ed119) with master (a9f248a)

Summary

✅ 59 untouched

Copy link

codecov bot commented Sep 17, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 98.75%. Comparing base (a9f248a) to head (83ed119).
⚠️ Report is 2 commits behind head on master.
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@            Coverage Diff             @@
##           master   #11515      +/-   ##
==========================================
+ Coverage   97.67%   98.75%   +1.08%     
==========================================
  Files         127      127              
  Lines       43354    43355       +1     
  Branches     2325     2325              
==========================================
+ Hits        42345    42815     +470     
+ Misses        826      385     -441     
+ Partials      183      155      -28     
Flag Coverage Δ
CI-GHA 98.63% <ø> (+1.04%) ⬆️
OS-Linux 98.37% <ø> (+0.77%) ⬆️
OS-Windows 96.69% <ø> (?)
OS-macOS 97.56% <ø> (?)
Py-3.10.11 97.21% <ø> (?)
Py-3.10.18 97.71% <ø> (+0.68%) ⬆️
Py-3.11.13 97.91% <ø> (+0.69%) ⬆️
Py-3.11.9 97.41% <ø> (?)
Py-3.12.10 97.51% <ø> (?)
Py-3.12.11 98.02% <ø> (+0.69%) ⬆️
Py-3.13.7 98.27% <ø> (+0.95%) ⬆️
Py-3.9.13 97.10% <ø> (?)
Py-3.9.23 97.60% <ø> (?)
Py-pypy3.9.19-7.3.16 92.03% <ø> (?)
VM-macos 97.56% <ø> (?)
VM-ubuntu 98.37% <ø> (+0.77%) ⬆️
VM-windows 96.69% <ø> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@github-actions github-actions bot merged commit a3f033a into master Sep 17, 2025
41 of 42 checks passed
@github-actions github-actions bot deleted the dependabot/pip/cryptography-46.0.1 branch September 17, 2025 10:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants