Release Python SDK Storages v1.1.1 - #1172
Draft
mgallego-keeper wants to merge 3 commits into
Draft
mgallego-keeper wants to merge 3 commits into
mgallego-keeper wants to merge 3 commits into
Conversation
Bug-fix and hardening release for the storage backends, plus publish
workflow alignment with the GCP/Oracle KMS template.
Fixes:
- KSM-959: add threading.RLock to all storage backends
- KSM-960: replace MD5 with SHA-256 and fix Azure AES-GCM nonce
- KSM-961: make encrypt/decrypt failures raise instead of returning empty
- KSM-962: delete_all() removes backing file instead of writing empty blob
- KSM-963: defer config update until after successful disk write
- KSM-964: flip decrypt_config() default from autosave=True to autosave=False
- KSM-965: use 'is not None' check to avoid treating {} as a decrypt trigger
- KSM-966: propagate AwsConfigProvider region and read errors
- KSM-967: AwsSecretStorage default constructor + json-without-privateKey handling
- KSM-969: lower Python floor 3.10 -> 3.9.2 to match GCP/Oracle storage
- KSM-972: raise a clear exception on a non-UTF8 corrupt config file
- KSM-977: populate err in __load_config so construction raises on AWS errors
- KSM-978: raise on empty __decrypt_buffer result in HsmNfast and AwsKms
- KSM-979: atomic write for __save_config and create_config_file_if_missing
CI:
- align v1.1.0 publish workflow with GCP/Oracle template
- harden publish workflow, pin wheel (CVE-2026-24049), add post-build import check
- bump Manifest CLI to v0.31.0, pin ksm-action SHA (v1.3.0)
…yptography 50.0.0 security bump Raises the cryptography floor from a transitive, unbounded resolution to a direct floor of 50.0.0, closing 4 open Dependabot alerts on sdk/python/storage/keeper_secrets_manager_storages/requirements.txt: - GHSA-537c-gmf6-5ccf (no CVE, High): vulnerable OpenSSL bundled in cryptography wheels, fixed in 48.0.1 - GHSA-jwv3-5hgf-82ww (CVE-2026-69249, High): duplicate self-signed intermediates cause exponential path-building, fixed in 49.0.0 - GHSA-m2h6-j472-rp4c (CVE-2026-69248, Medium): verifier accepts wildcard DNS names, allowing escape from permittedSubtrees, fixed in 49.0.0 - GHSA-g6cj-pr64-35w5 (CVE-2026-69247, High): PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing, fixed in 50.0.0 requirements.txt regenerated via uv pip compile per project convention rather than hand-edited. BREAKING CHANGE: cryptography>=49.0.0 drops Python 3.9 support, so this raises the package's minimum Python version from 3.9.2 to 3.10, matching the same floor move already made on the sibling Oracle KMS and GCP KMS storage packages (PRs #1069 and #1068). CI workflows for this package updated to stop testing on Python 3.9. KSM-1239
mgallego-keeper
marked this pull request as draft
September 16, 2026 16:58
The previous commit assumed cryptography>=49 drops Python 3.9 support and raised requires-python to >=3.10 on that basis. Checked cryptography 50.0.1's actual PyPI metadata (requires_python: !=3.9.0,!=3.9.1,>=3.9) and verified locally with uv pip compile --python-version 3.9.2: it resolves cleanly with cryptography==50.0.1. The floor bump was not needed, so this reverts it: setup.py python_requires back to >=3.9.2, the 3.9 classifier restored, both CI workflow matrices restored to include 3.9, and requirements.txt regenerated at the 3.9.2 floor. The cryptography>=50.0.0 security fix itself is unchanged and still closes all 4 open Dependabot alerts on this manifest. This release is no longer a breaking change. KSM-1239
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Security fix: raises the cryptography floor to 50.0.0, closing all 4 open Dependabot alerts on
sdk/python/storage/keeper_secrets_manager_storages/requirements.txt.cryptographyis now declared as a direct dependency (previously only pulled in transitively viakeeper-secrets-manager-core), following this repo's KSM-1235 policy of bounding security-relevant dependency floors.requirements.txtregenerated viauv pip compileper project convention rather than hand-edited.Python 3.9.2 remains supported.
cryptography>=50.0.0's PyPI metadata isrequires_python: !=3.9.0,!=3.9.1,>=3.9, so the earlier assumption in this PR's first commit that a Python floor bump to 3.10 was needed was incorrect; verified by resolving locally at--python-version 3.9.2. See KSM-1419 for a separate, unrelated Python 3.9 exposure (unflagged urllib3 2.6.3 on this manifest) that needs its own floor decision.KSM-1239
Breaking Changes
None. This release does not change the minimum supported Python version.