Skip to content

fix(attack-surface-management): stop downgrading cryptography and dnspython - #158

Merged
monoxgas merged 1 commit into
mainfrom
nick/asm-relax-dnspython-pyopenssl
Sep 29, 2026
Merged

monoxgas merged 1 commit into
mainfrom
nick/asm-relax-dnspython-pyopenssl

Conversation

@monoxgas

Copy link
Copy Markdown
Contributor

Summary

  • dnspython>=2.7.0,<2.8.0 → dnspython>=2.7.0,<2.9.0, matching bbot 3.0.2's own requirement.
  • pyOpenSSL~=25.3.0 → pyOpenSSL>=25.3.0,<27. pyOpenSSL 26.4.0 allows cryptography 49–50.
  • Version 2.0.1 → 2.0.2 in capability.yaml and pyproject.toml.

Why

The runtime installs a capability's dependencies.python beside the SDK without constraints. With the old pins, binding this capability downgraded the SDK's locked cryptography 50.0.1 to 46.0.7, and dnspython 2.8.0 to 2.7.0. osv-scanner reports pyOpenSSL 25.3.0 (2 advisories, max 9.8) and cryptography 46.0.7 (4 advisories, max 8.7).

Verification

Python 3.13, linux/amd64: the SDK installed from packages/sdk/uv.lock at dreadnode-tiger 7a8d3bf25, then this capability's pins installed unconstrained, the way the runtime install step does it.

cryptography pyopenssl dnspython tests
this branch 50.0.1 26.4.0 2.8.0 15 passed
main 46.0.7 25.3.0 2.7.0 15 passed

Not in this PR

Both of these are the same on main and on this branch:

  • badsecrets~=0.13.47 brings in django 4.2.30 (7 advisories, max 6.9). badsecrets 1.2.1 requires django>=5.2.15, but that is a major-version change and needs the capability owner to verify.
  • With this capability installed, uv pip check reports dreadnode requires xmltodict>=1.0.2, but 0.14.2 is installed. Something in the capability's dependency tree holds xmltodict below the SDK's minimum.

🤖 Generated with Claude Code

…python

The capability pinned pyOpenSSL~=25.3.0, which requires cryptography<47,
and dnspython<2.8. The runtime installs capability pins beside the SDK
without constraints, so binding this capability downgraded the SDK's
cryptography 50.0.1 to 46.0.7 and dnspython 2.8.0 to 2.7.0. pyOpenSSL
25.3.0 and cryptography 46.0.7 both carry known advisories.

bbot 3.0.2 needs only dnspython>=2.7.0,<2.9.0 and does not pin pyOpenSSL.
Allow pyOpenSSL 26.x and dnspython 2.8.x. Bump to 2.0.2.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@monoxgas
monoxgas merged commit 32db51b into main Sep 29, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant