Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

py3-cryptography/43.0.0 package update #24354

Merged
merged 1 commit into from
Jul 20, 2024

Conversation

octo-sts[bot]
Copy link
Contributor

@octo-sts octo-sts bot commented Jul 20, 2024

@octo-sts octo-sts bot added request-version-update request for a newer version of a package automated pr labels Jul 20, 2024
Copy link
Contributor

Package py3-cryptography: Click to expand/collapse

Package py3-cryptography:

.PKGINFO metadata:

  (
  	"""
- 	# Generated by melange v0.16.15-23-geb4d817
+ 	# Generated by melange
  	pkgname = py3-cryptography
- 	pkgver = 42.0.8-r0
+ 	pkgver = 43.0.0-r0
  	arch = x86_64
- 	size = 4506653
+ 	size = 4890151
  	origin = py3-cryptography
  	pkgdesc = cryptography is a package which provides cryptographic recipes and primitives to Python developers.
  	url = 
- 	commit = 9948db0478e8729b646811c906e6c08e36a9197c
- 	builddate = 1717612554
+ 	commit = cb50bdcac09cd06e69db60a30acf952012d91b4f
  	license = Apache-2.0 OR BSD-3-Clause
  	depend = py3-cffi
  	... // 4 identical lines
  	depend = so:libgcc_s.so.1
  	depend = so:libssl.so.3
- 	datahash = be31c347350ac8bfbb57dfe3cf6acb4ad0ff53d1b801ace69da146309fcb0059
+ 	datahash = 9524a8ca87a53315a6d22a52f98e802828238e031058ef4b2d77247b829a3fcd
  	"""
  )

Added: /usr/lib/python3.12/site-packages/cryptography/hazmat/bindings/_rust/openssl/ciphers.pyi
Added: /usr/lib/python3.12/site-packages/cryptography/hazmat/bindings/_rust/pkcs12.pyi
Added: /usr/lib/python3.12/site-packages/cryptography/hazmat/bindings/_rust/test_support.pyi
Added: /usr/lib/python3.12/site-packages/cryptography/hazmat/bindings/_rust.abi3.so
Added: /usr/lib/python3.12/site-packages/cryptography/hazmat/decrepit/init.py
Added: /usr/lib/python3.12/site-packages/cryptography/hazmat/decrepit/ciphers/init.py
Added: /usr/lib/python3.12/site-packages/cryptography/hazmat/decrepit/ciphers/algorithms.py
Added: /usr/lib/python3.12/site-packages/cryptography-43.0.0.dist-info/METADATA
Added: /usr/lib/python3.12/site-packages/cryptography-43.0.0.dist-info/RECORD
Added: /usr/lib/python3.12/site-packages/cryptography-43.0.0.dist-info/WHEEL
Added: /usr/lib/python3.12/site-packages/cryptography-43.0.0.dist-info/license_files/LICENSE
Added: /usr/lib/python3.12/site-packages/cryptography-43.0.0.dist-info/license_files/LICENSE.APACHE
Added: /usr/lib/python3.12/site-packages/cryptography-43.0.0.dist-info/license_files/LICENSE.BSD
Modified: /usr/lib/python3.12/site-packages/cryptography/about.py
Modified: /usr/lib/python3.12/site-packages/cryptography/init.py
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/_oid.py
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/backends/openssl/backend.py
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/bindings/_rust/init.pyi
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/bindings/_rust/asn1.pyi
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/bindings/_rust/ocsp.pyi
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/bindings/_rust/openssl/init.pyi
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/bindings/_rust/openssl/aead.pyi
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/bindings/_rust/openssl/keys.pyi
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/bindings/_rust/pkcs7.pyi
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/bindings/_rust/x509.pyi
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/bindings/openssl/_conditional.py
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/bindings/openssl/binding.py
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/primitives/_cipheralgorithm.py
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/primitives/asymmetric/ec.py
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/primitives/asymmetric/rsa.py
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/primitives/ciphers/init.py
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/primitives/ciphers/aead.py
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/primitives/ciphers/algorithms.py
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/primitives/ciphers/base.py
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/primitives/ciphers/modes.py
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/primitives/hashes.py
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/primitives/kdf/kbkdf.py
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/primitives/kdf/pbkdf2.py
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/primitives/keywrap.py
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/primitives/padding.py
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/primitives/serialization/init.py
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/primitives/serialization/pkcs12.py
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/primitives/serialization/pkcs7.py
Modified: /usr/lib/python3.12/site-packages/cryptography/hazmat/primitives/serialization/ssh.py
Modified: /usr/lib/python3.12/site-packages/cryptography/utils.py
Modified: /usr/lib/python3.12/site-packages/cryptography/x509/init.py
Modified: /usr/lib/python3.12/site-packages/cryptography/x509/base.py
Modified: /usr/lib/python3.12/site-packages/cryptography/x509/extensions.py
Modified: /usr/lib/python3.12/site-packages/cryptography/x509/name.py
Modified: /usr/lib/python3.12/site-packages/cryptography/x509/ocsp.py
Modified: /usr/lib/python3.12/site-packages/cryptography/x509/oid.py
Modified: /usr/lib/python3.12/site-packages/cryptography/x509/verification.py
Deleted: /usr/lib/python3.12/site-packages/cryptography/hazmat/backends/openssl/aead.py
Deleted: /usr/lib/python3.12/site-packages/cryptography/hazmat/backends/openssl/ciphers.py
Deleted: /usr/lib/python3.12/site-packages/cryptography/hazmat/backends/openssl/decode_asn1.py
Deleted: /usr/lib/python3.12/site-packages/cryptography/hazmat/bindings/_rust.cpython-312-x86_64-linux-gnu.so
Deleted: /usr/lib/python3.12/site-packages/cryptography-42.0.8.dist-info/LICENSE
Deleted: /usr/lib/python3.12/site-packages/cryptography-42.0.8.dist-info/LICENSE.APACHE
Deleted: /usr/lib/python3.12/site-packages/cryptography-42.0.8.dist-info/LICENSE.BSD
Deleted: /usr/lib/python3.12/site-packages/cryptography-42.0.8.dist-info/METADATA
Deleted: /usr/lib/python3.12/site-packages/cryptography-42.0.8.dist-info/RECORD
Deleted: /usr/lib/python3.12/site-packages/cryptography-42.0.8.dist-info/WHEEL
Deleted: /usr/lib/python3.12/site-packages/cryptography-42.0.8.dist-info/top_level.txt

bincapz found differences: Click to expand/collapse

Changed: /tmp/wolfictl-apk-2633327142/py3-cryptography/usr/lib/python3.12/site-packages/cryptography/hazmat/bindings/_rust/pkcs12.pyi [⚠️ MEDIUM → ✅ LOW]

1 new behaviors

RISK KEY DESCRIPTION EVIDENCE
+LOW ref/words/password references a 'password' password

2 removed behaviors

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/download download files downloadLocation
-LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/4bbe07ab374a2ae0737f2b2f1eae

Changed: /tmp/wolfictl-apk-2633327142/py3-cryptography/var/lib/db/sbom/py3-cryptography-43.0.0-r0.spdx.json

1 new behaviors

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/download download files downloadLocation

17 removed behaviors

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM 3P/threat_hunting/checkplease references 'CheckPlease' tool, by mthcht $string1_CheckPlease_offensive_tool_keyword
-MEDIUM net/http/post submit content to websites POST
http
-MEDIUM net/ssh Uses SSH (secure shell) service SSH
-MEDIUM procfs/self/exe gets executable associated to this process /proc/self/exe
-MEDIUM ref/path/dev path reference within /dev /dev/uraH
/dev/urandomInvalid
/dev/urandomfailed
-MEDIUM ref/path/tmp path reference within /tmp /tmp/build-via-sdist-g65pq0gg/cryptography-42.0.8/src/rust/cryptograp
/tmp/build-via-sdist-g65pq0gg/cryptography-42.0.8/src/rust/target/rel
-LOW crypto/aes Supports AES (Advanced Encryption Standard) AES
-LOW crypto/ed25519 Elliptic curve algorithm used by TLS and SSH ed25519
-LOW dylib/iterate iterate over list of shared objects dl_iterate_phdr
-LOW encoding/base64 Supports base64 encoded strings base64
-LOW fs/link/read read value of a symbolic link readlink
-LOW fs/symlink/resolve resolves symbolic links realpath
-LOW net/socket/listen listen on a socket accept
listen
-LOW process/thread_local_storage Uses glibc thread local storage __tls_get_addr
-LOW ref/path/hidden possible hidden file path /home/build/.cargo
/usr/lib/debug/.build-id
-LOW ref/words/password references a 'password' password_callback
pem_password_cb
-LOW secrets/private_key References private keys PRIVATE_KEY
private_key

Changed: /tmp/wolfictl-apk-2633327142/py3-cryptography/usr/lib/python3.12/site-packages/cryptography/hazmat/decrepit/init.py [⚠️ MEDIUM → ✅ ]

18 removed behaviors

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM 3P/threat_hunting/checkplease references 'CheckPlease' tool, by mthcht $string1_CheckPlease_offensive_tool_keyword
-MEDIUM net/http/post submit content to websites POST
http
-MEDIUM net/ssh Uses SSH (secure shell) service SSH
-MEDIUM procfs/self/exe gets executable associated to this process /proc/self/exe
-MEDIUM ref/path/dev path reference within /dev /dev/uraH
/dev/urandomInvalid
/dev/urandomfailed
-MEDIUM ref/path/tmp path reference within /tmp /tmp/build-via-sdist-g65pq0gg/cryptography-42.0.8/src/rust/cryptograp
/tmp/build-via-sdist-g65pq0gg/cryptography-42.0.8/src/rust/target/rel
-LOW crypto/aes Supports AES (Advanced Encryption Standard) AES
-LOW crypto/ed25519 Elliptic curve algorithm used by TLS and SSH ed25519
-LOW dylib/iterate iterate over list of shared objects dl_iterate_phdr
-LOW encoding/base64 Supports base64 encoded strings base64
-LOW fs/link/read read value of a symbolic link readlink
-LOW fs/symlink/resolve resolves symbolic links realpath
-LOW net/socket/listen listen on a socket accept
listen
-LOW process/thread_local_storage Uses glibc thread local storage __tls_get_addr
-LOW ref/path/hidden possible hidden file path /home/build/.cargo
/usr/lib/debug/.build-id
-LOW ref/site/url contains embedded HTTPS URLs https://cryptography.io/en/latest/faq/
PyO3/pyo3#576
pyca/cryptography#8996
pyca/cryptography#9253
-LOW ref/words/password references a 'password' password_callback
pem_password_cb
-LOW secrets/private_key References private keys PRIVATE_KEY
private_key

Changed: /tmp/wolfictl-apk-2633327142/py3-cryptography/usr/lib/python3.12/site-packages/cryptography/hazmat/bindings/_rust/test_support.pyi [⚠️ MEDIUM → ✅ ]

18 removed behaviors

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM 3P/threat_hunting/checkplease references 'CheckPlease' tool, by mthcht $string1_CheckPlease_offensive_tool_keyword
-MEDIUM net/http/post submit content to websites POST
http
-MEDIUM net/ssh Uses SSH (secure shell) service SSH
-MEDIUM procfs/self/exe gets executable associated to this process /proc/self/exe
-MEDIUM ref/path/dev path reference within /dev /dev/uraH
/dev/urandomInvalid
/dev/urandomfailed
-MEDIUM ref/path/tmp path reference within /tmp /tmp/build-via-sdist-g65pq0gg/cryptography-42.0.8/src/rust/cryptograp
/tmp/build-via-sdist-g65pq0gg/cryptography-42.0.8/src/rust/target/rel
-LOW crypto/aes Supports AES (Advanced Encryption Standard) AES
-LOW crypto/ed25519 Elliptic curve algorithm used by TLS and SSH ed25519
-LOW dylib/iterate iterate over list of shared objects dl_iterate_phdr
-LOW encoding/base64 Supports base64 encoded strings base64
-LOW fs/link/read read value of a symbolic link readlink
-LOW fs/symlink/resolve resolves symbolic links realpath
-LOW net/socket/listen listen on a socket accept
listen
-LOW process/thread_local_storage Uses glibc thread local storage __tls_get_addr
-LOW ref/path/hidden possible hidden file path /home/build/.cargo
/usr/lib/debug/.build-id
-LOW ref/site/url contains embedded HTTPS URLs https://cryptography.io/en/latest/faq/
PyO3/pyo3#576
pyca/cryptography#8996
pyca/cryptography#9253
-LOW ref/words/password references a 'password' password_callback
pem_password_cb
-LOW secrets/private_key References private keys PRIVATE_KEY
private_key

Changed: /tmp/wolfictl-apk-2633327142/py3-cryptography/usr/lib/python3.12/site-packages/cryptography/hazmat/bindings/_rust/openssl/ciphers.pyi [⚠️ MEDIUM → ✅ ]

18 removed behaviors

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM 3P/threat_hunting/checkplease references 'CheckPlease' tool, by mthcht $string1_CheckPlease_offensive_tool_keyword
-MEDIUM net/http/post submit content to websites POST
http
-MEDIUM net/ssh Uses SSH (secure shell) service SSH
-MEDIUM procfs/self/exe gets executable associated to this process /proc/self/exe
-MEDIUM ref/path/dev path reference within /dev /dev/uraH
/dev/urandomInvalid
/dev/urandomfailed
-MEDIUM ref/path/tmp path reference within /tmp /tmp/build-via-sdist-g65pq0gg/cryptography-42.0.8/src/rust/cryptograp
/tmp/build-via-sdist-g65pq0gg/cryptography-42.0.8/src/rust/target/rel
-LOW crypto/aes Supports AES (Advanced Encryption Standard) AES
-LOW crypto/ed25519 Elliptic curve algorithm used by TLS and SSH ed25519
-LOW dylib/iterate iterate over list of shared objects dl_iterate_phdr
-LOW encoding/base64 Supports base64 encoded strings base64
-LOW fs/link/read read value of a symbolic link readlink
-LOW fs/symlink/resolve resolves symbolic links realpath
-LOW net/socket/listen listen on a socket accept
listen
-LOW process/thread_local_storage Uses glibc thread local storage __tls_get_addr
-LOW ref/path/hidden possible hidden file path /home/build/.cargo
/usr/lib/debug/.build-id
-LOW ref/site/url contains embedded HTTPS URLs https://cryptography.io/en/latest/faq/
PyO3/pyo3#576
pyca/cryptography#8996
pyca/cryptography#9253
-LOW ref/words/password references a 'password' password_callback
pem_password_cb
-LOW secrets/private_key References private keys PRIVATE_KEY
private_key

Changed: /tmp/wolfictl-apk-2633327142/py3-cryptography/usr/lib/python3.12/site-packages/cryptography/hazmat/bindings/_rust.abi3.so

17 new behaviors

RISK KEY DESCRIPTION EVIDENCE
+MEDIUM net/http/post submit content to websites POST
http
+MEDIUM net/ssh Uses SSH (secure shell) service SSH
+MEDIUM procfs/self/exe gets executable associated to this process /proc/self/exe
+MEDIUM ref/path/dev path reference within /dev /dev/uraH
/dev/urandomInvalid
/dev/urandomfailed
+MEDIUM ref/path/tmp path reference within /tmp /tmp/build-via-sdist-iby_1oj4/cryptography-43.0.0/src/rust/cryptograp
+LOW crypto/aes Supports AES (Advanced Encryption Standard) AES
+LOW crypto/ed25519 Elliptic curve algorithm used by TLS and SSH ed25519
+LOW dylib/iterate iterate over list of shared objects dl_iterate_phdr
+LOW encoding/base64 Supports base64 encoded strings base64
+LOW fs/link/read read value of a symbolic link readlink
+LOW fs/symlink/resolve resolves symbolic links realpath
+LOW hash/blake2b Uses blake2b encryption algorithm blake2b
+LOW net/socket/listen listen on a socket accept
listen
+LOW process/thread_local_storage Uses glibc thread local storage __tls_get_addr
+LOW ref/path/hidden possible hidden file path /home/build/.cargo
/usr/lib/debug/.build-id
+LOW ref/words/password references a 'password' password_callback
pem_password_cb
+LOW secrets/private_key References private keys PRIVATE_KEY
private_key

1 removed behaviors

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/download download files downloadLocation

Changed: /tmp/wolfictl-apk-2633327142/py3-cryptography/usr/lib/python3.12/site-packages/cryptography/hazmat/decrepit/ciphers/init.py [⚠️ MEDIUM → ✅ ]

18 removed behaviors

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM 3P/threat_hunting/checkplease references 'CheckPlease' tool, by mthcht $string1_CheckPlease_offensive_tool_keyword
-MEDIUM net/http/post submit content to websites POST
http
-MEDIUM net/ssh Uses SSH (secure shell) service SSH
-MEDIUM procfs/self/exe gets executable associated to this process /proc/self/exe
-MEDIUM ref/path/dev path reference within /dev /dev/uraH
/dev/urandomInvalid
/dev/urandomfailed
-MEDIUM ref/path/tmp path reference within /tmp /tmp/build-via-sdist-g65pq0gg/cryptography-42.0.8/src/rust/cryptograp
/tmp/build-via-sdist-g65pq0gg/cryptography-42.0.8/src/rust/target/rel
-LOW crypto/aes Supports AES (Advanced Encryption Standard) AES
-LOW crypto/ed25519 Elliptic curve algorithm used by TLS and SSH ed25519
-LOW dylib/iterate iterate over list of shared objects dl_iterate_phdr
-LOW encoding/base64 Supports base64 encoded strings base64
-LOW fs/link/read read value of a symbolic link readlink
-LOW fs/symlink/resolve resolves symbolic links realpath
-LOW net/socket/listen listen on a socket accept
listen
-LOW process/thread_local_storage Uses glibc thread local storage __tls_get_addr
-LOW ref/path/hidden possible hidden file path /home/build/.cargo
/usr/lib/debug/.build-id
-LOW ref/site/url contains embedded HTTPS URLs https://cryptography.io/en/latest/faq/
PyO3/pyo3#576
pyca/cryptography#8996
pyca/cryptography#9253
-LOW ref/words/password references a 'password' password_callback
pem_password_cb
-LOW secrets/private_key References private keys PRIVATE_KEY
private_key

Changed: /tmp/wolfictl-apk-2633327142/py3-cryptography/usr/lib/python3.12/site-packages/cryptography/hazmat/decrepit/ciphers/algorithms.py [⚠️ MEDIUM → ✅ ]

2 removed behaviors

RISK KEY DESCRIPTION EVIDENCE
-MEDIUM net/download download files downloadLocation
-LOW ref/site/url contains embedded HTTPS URLs https://spdx.org/spdxdocs/chainguard/melange/4bbe07ab374a2ae0737f2b2f1eae

@rawlingsj rawlingsj merged commit b92204b into main Jul 20, 2024
8 checks passed
@rawlingsj rawlingsj deleted the wolfictl-6a8a55f7-d65a-4ca0-ae0f-1069afa3c2ce branch July 20, 2024 17:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants