The python-cryptography rpms
Find a file
Jeremy Cline 09809af65a
Update to v46.0.5
Changelog (https://cryptography.io/en/latest/changelog/#v46-0-5)

 - An attacker could create a malicious public key that reveals portions
   of your private key when using certain uncommon elliptic curves
   (binary curves). This version now includes additional security checks
   to prevent this attack. This issue only affects binary elliptic
   curves, which are rarely used in real-world applications. Credit to
   **XlabAI Team of Tencent Xuanwu Lab and Atuin Automated Vulnerability
   Discovery Engine** for reporting the issue. **CVE-2026-26007**

 - Support for SECT binary elliptic curves is deprecated and will be
   removed in the next release.
2026-02-10 15:15:14 -05:00
.gitignore Update to v46.0.5 2026-02-10 15:15:14 -05:00
changelog Switch to autorelease and autochangelog macros 2024-07-03 10:27:54 -04:00
conftest-skipper.py Skip iso8601 and pretend tests on RHEL 2021-02-12 16:47:08 +01:00
python-cryptography.spec Update to v46.0.5 2026-02-10 15:15:14 -05:00
README.md Update to 3.4.7, use vectors from sources (#1952024) 2021-04-22 08:07:57 +02:00
sources Update to v46.0.5 2026-02-10 15:15:14 -05:00
vendor_rust.py Update to 42.0.8, resolves RHBZ#2251816" 2024-07-03 09:25:42 -04:00

PyCA cryptography

https://cryptography.io/en/latest/

Packaging python-cryptography

The example assumes

  • Fedora Rawhide (f34)
  • PyCA cryptography release 3.4
  • Update Bugzilla issue is RHBZ#00000001

Build new python-cryptography

Switch and update branch

fedpkg switch-branch rawhide
fedpkg pull

Bump version and get sources

rpmdev-bumpspec -c "Update to 3.4 (#00000001)" -n 3.4 python-cryptography.spec
spectool -gf python-cryptography.spec

Upload new source

fedpkg new-sources cryptography-3.4.tar.gz

Commit changes

fedpkg commit --clog
fedpkg push

Build

fedpkg build

RHEL/CentOS builds

RHEL and CentOS use a different approach for Rust crates packaging than Fedora. On Fedora Rust dependencies are packaged as RPMs, e.g. rust-pyo3+default-devel RPM. These packages don't exist on RHEL and CentOS. Instead python-cryptography uses a tar ball with vendored crates. The tar ball is created by a script:

./vendor_rust.py
rhpkg upload cryptography-3.4-vendor.tar.bz2