From ed6520ccfe8ac2dd70da280eeff6d4b850aa2d41 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Wed, 24 Jun 2026 18:16:47 -0400 Subject: [PATCH] fix(deps): bump cryptography 46.0.7 -> 48.0.1 (GHSA-537c-gmf6-5ccf) pip-audit flagged the 46.0.7 pin: wheels before 48.0.1 statically link a vulnerable OpenSSL. 48.0.1 is the fix version. --- requirements.txt | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index ecaddd7..4e854e8 100644 --- a/requirements.txt +++ b/requirements.txt @@ -14,7 +14,8 @@ uvicorn==0.46.0 # (agent_team/github_app.py): RS256 JWT (PyJWT) signed with the App private key, # exchanged for a short-lived installation token. cryptography backs RS256. PyJWT==2.13.0 -cryptography==46.0.7 +# >=48.0.1: earlier wheels statically link a vulnerable OpenSSL (GHSA-537c-gmf6-5ccf). +cryptography==48.0.1 # Runtime HTTP client for the agent-team P3 App-dispatch seams # (github_app.mint_installation_token, dispatcher.app_workflow_dispatcher, # dispatcher.app_run_locator) and the CI fetcher/transport. Pinned first-class