Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Comments

⬆ Bump cryptography from 46.0.4 to 46.0.5#14892

Merged
YuriiMotov merged 2 commits intomasterfrom
dependabot/uv/cryptography-46.0.5
Feb 13, 2026
Merged

⬆ Bump cryptography from 46.0.4 to 46.0.5#14892
YuriiMotov merged 2 commits intomasterfrom
dependabot/uv/cryptography-46.0.5

Conversation

@dependabot
Copy link
Contributor

@dependabotdependabotbot commented on behalf ofgithubFeb 11, 2026

Bumpscryptography from 46.0.4 to 46.0.5.

Changelog

Sourced fromcryptography's changelog.

46.0.5 - 2026-02-10

* An attacker could create a malicious public key that reveals portions of your  private key when using certain uncommon elliptic curves (binary curves).  This version now includes additional security checks to prevent this attack.  This issue only affects binary elliptic curves, which are rarely used in  real-world applications. Credit to **XlabAI Team of Tencent Xuanwu Lab and  Atuin Automated Vulnerability Discovery Engine** for reporting the issue.  **CVE-2026-26007*** Support for ``SECT*`` binary elliptic curves is deprecated and will be  removed in the next release.

.. v46-0-4:

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting@dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from theSecurity Alerts page.

Bumps [cryptography](https://github.com/pyca/cryptography) from 46.0.4 to 46.0.5.- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)- [Commits](pyca/cryptography@46.0.4...46.0.5)---updated-dependencies:- dependency-name: cryptography  dependency-version: 46.0.5  dependency-type: indirect...Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotbot added dependenciesPull requests that update a dependency file python:uvPull requests that update python:uv code labelsFeb 11, 2026
@github-actions
Copy link
Contributor

github-actionsbot commentedFeb 11, 2026
edited
Loading

📝 Docs preview

Last commit3562b86 at:https://294fac80.fastapitiangolo.pages.dev

@codspeed-hq
Copy link

codspeed-hqbot commentedFeb 11, 2026
edited
Loading

Merging this PR willnot alter performance

✅ 20 untouched benchmarks


Comparingdependabot/uv/cryptography-46.0.5 (3562b86) withmaster (db32827)1

Open in CodSpeed

Footnotes

  1. No successful run was found onmaster (7c4b134) during the generation of this report, sodb32827 was used instead as the comparison base. There might be some changes unrelated to this pull request in this report.

@YuriiMotovYuriiMotov merged commitb93c964 intomasterFeb 13, 2026
39 checks passed
@YuriiMotovYuriiMotov deleted the dependabot/uv/cryptography-46.0.5 branchFebruary 13, 2026 07:04
Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment

Reviewers

No reviews

Assignees

No one assigned

Labels

dependenciesPull requests that update a dependency fileinternalpython:uvPull requests that update python:uv code

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

1 participant

@YuriiMotov

[8]ページ先頭

©2009-2026 Movatter.jp