Skip to content

Release Python SDK Storages v1.1.1 - #1172

Draft
mgallego-keeper wants to merge 3 commits into
masterfrom
release/sdk/python/storage/v1.1.1
Draft

mgallego-keeper wants to merge 3 commits into
masterfrom
release/sdk/python/storage/v1.1.1

Conversation

@mgallego-keeper

@mgallego-keeper mgallego-keeper commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Security fix: raises the cryptography floor to 50.0.0, closing all 4 open Dependabot alerts on sdk/python/storage/keeper_secrets_manager_storages/requirements.txt.

cryptography is now declared as a direct dependency (previously only pulled in transitively via keeper-secrets-manager-core), following this repo's KSM-1235 policy of bounding security-relevant dependency floors.

requirements.txt regenerated via uv pip compile per project convention rather than hand-edited.

Python 3.9.2 remains supported. cryptography>=50.0.0's PyPI metadata is requires_python: !=3.9.0,!=3.9.1,>=3.9, so the earlier assumption in this PR's first commit that a Python floor bump to 3.10 was needed was incorrect; verified by resolving locally at --python-version 3.9.2. See KSM-1419 for a separate, unrelated Python 3.9 exposure (unflagged urllib3 2.6.3 on this manifest) that needs its own floor decision.

KSM-1239

Breaking Changes

None. This release does not change the minimum supported Python version.

stas-schaller and others added 2 commits June 1, 2026 12:54
Bug-fix and hardening release for the storage backends, plus publish
workflow alignment with the GCP/Oracle KMS template.

Fixes:
- KSM-959: add threading.RLock to all storage backends
- KSM-960: replace MD5 with SHA-256 and fix Azure AES-GCM nonce
- KSM-961: make encrypt/decrypt failures raise instead of returning empty
- KSM-962: delete_all() removes backing file instead of writing empty blob
- KSM-963: defer config update until after successful disk write
- KSM-964: flip decrypt_config() default from autosave=True to autosave=False
- KSM-965: use 'is not None' check to avoid treating {} as a decrypt trigger
- KSM-966: propagate AwsConfigProvider region and read errors
- KSM-967: AwsSecretStorage default constructor + json-without-privateKey handling
- KSM-969: lower Python floor 3.10 -> 3.9.2 to match GCP/Oracle storage
- KSM-972: raise a clear exception on a non-UTF8 corrupt config file
- KSM-977: populate err in __load_config so construction raises on AWS errors
- KSM-978: raise on empty __decrypt_buffer result in HsmNfast and AwsKms
- KSM-979: atomic write for __save_config and create_config_file_if_missing

CI:
- align v1.1.0 publish workflow with GCP/Oracle template
- harden publish workflow, pin wheel (CVE-2026-24049), add post-build import check
- bump Manifest CLI to v0.31.0, pin ksm-action SHA (v1.3.0)
…yptography 50.0.0 security bump

Raises the cryptography floor from a transitive, unbounded resolution
to a direct floor of 50.0.0, closing 4 open Dependabot alerts on
sdk/python/storage/keeper_secrets_manager_storages/requirements.txt:

- GHSA-537c-gmf6-5ccf (no CVE, High): vulnerable OpenSSL bundled in
  cryptography wheels, fixed in 48.0.1
- GHSA-jwv3-5hgf-82ww (CVE-2026-69249, High): duplicate self-signed
  intermediates cause exponential path-building, fixed in 49.0.0
- GHSA-m2h6-j472-rp4c (CVE-2026-69248, Medium): verifier accepts
  wildcard DNS names, allowing escape from permittedSubtrees, fixed
  in 49.0.0
- GHSA-g6cj-pr64-35w5 (CVE-2026-69247, High): PKCS#7 EnvelopedData
  decryption exposes a Bleichenbacher oracle through distinguishable
  errors and timing, fixed in 50.0.0

requirements.txt regenerated via uv pip compile per project
convention rather than hand-edited.

BREAKING CHANGE: cryptography>=49.0.0 drops Python 3.9 support, so
this raises the package's minimum Python version from 3.9.2 to
3.10, matching the same floor move already made on the sibling
Oracle KMS and GCP KMS storage packages (PRs #1069 and #1068). CI
workflows for this package updated to stop testing on Python 3.9.

KSM-1239
@mgallego-keeper mgallego-keeper changed the title fix(storage): upgrade cryptography to 50.0.0 and raise Python floor to 3.10 (KSM-1239) Release Python SDK Storage v1.1.1 Sep 16, 2026
@mgallego-keeper
mgallego-keeper marked this pull request as draft September 16, 2026 16:58
@mgallego-keeper mgallego-keeper changed the title Release Python SDK Storage v1.1.1 Release Python SDK Storages v1.1.1 Sep 16, 2026
The previous commit assumed cryptography>=49 drops Python 3.9 support
and raised requires-python to >=3.10 on that basis. Checked cryptography
50.0.1's actual PyPI metadata (requires_python: !=3.9.0,!=3.9.1,>=3.9)
and verified locally with uv pip compile --python-version 3.9.2: it
resolves cleanly with cryptography==50.0.1. The floor bump was not
needed, so this reverts it: setup.py python_requires back to >=3.9.2,
the 3.9 classifier restored, both CI workflow matrices restored to
include 3.9, and requirements.txt regenerated at the 3.9.2 floor.

The cryptography>=50.0.0 security fix itself is unchanged and still
closes all 4 open Dependabot alerts on this manifest. This release is
no longer a breaking change.

KSM-1239
@mgallego-keeper mgallego-keeper changed the title Release Python SDK Storages v1.1.1 fix(storage): upgrade cryptography to 50.0.0 (KSM-1239) Sep 16, 2026
@mgallego-keeper mgallego-keeper changed the title fix(storage): upgrade cryptography to 50.0.0 (KSM-1239) Release Python SDK Storages v1.1.1 Sep 16, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants