Skip to content

build(deps): bump bcrypt from 3.1.7 to 5.0.0 in the security group across 1 directory - #595

Merged
MateoLostanlen merged 1 commit into
mainfrom
dependabot/uv/main/security-d135905752
May 15, 2026
Merged

MateoLostanlen merged 1 commit into
mainfrom
dependabot/uv/main/security-d135905752

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 15, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the security group with 1 update in the / directory: bcrypt.

Updates bcrypt from 3.1.7 to 5.0.0

Changelog

Sourced from bcrypt's changelog.

5.0.0

  • Bumped MSRV to 1.74.
  • Added support for Python 3.14 and free-threaded Python 3.14.
  • Added support for Windows on ARM.
  • Passing hashpw a password longer than 72 bytes now raises a ValueError. Previously the password was silently truncated, following the behavior of the original OpenBSD bcrypt implementation.

4.3.0

  • Dropped support for Python 3.7.
  • We now support free-threaded Python 3.13.
  • We now support PyPy 3.11.
  • We now publish wheels for free-threaded Python 3.13, for PyPy 3.11 on manylinux, and for ARMv7l on manylinux.

4.2.1

  • Bump Rust dependency versions - this should resolve crashes on Python 3.13 free-threaded builds.
  • We no longer build manylinux wheels for PyPy 3.9.

4.2.0

  • Bump Rust dependency versions
  • Removed the BCRYPT_ALLOW_RUST_163 environment variable.

4.1.3

  • Bump Rust dependency versions

4.1.2

  • Publish both py37 and py39 wheels. This should resolve some errors relating to initializing a module multiple times per process.

4.1.1

  • Fixed the type signature on the kdf method.
  • Fixed packaging bug on Windows.
  • Fixed incompatibility with passlib package detection assumptions.

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file type: misc labels May 15, 2026
@github-actions github-actions Bot added the topic: build Related to build, installation & CI label May 15, 2026
@socket-security

socket-security Bot commented May 15, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedbcrypt@​3.1.7 ⏵ 5.0.0100 +1100100100100

View full report

@dependabot dependabot Bot changed the title build(deps): bump bcrypt from 3.1.7 to 5.0.0 in the security group build(deps): bump bcrypt from 3.1.7 to 5.0.0 in the security group across 1 directory May 15, 2026
@dependabot
dependabot Bot force-pushed the dependabot/uv/main/security-d135905752 branch from a263173 to 1b59043 Compare May 15, 2026 11:13
@codecov

codecov Bot commented May 15, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 90.12%. Comparing base (5be2159) to head (4b7908a).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main     #595      +/-   ##
==========================================
+ Coverage   90.09%   90.12%   +0.03%     
==========================================
  Files          55       55              
  Lines        2503     2512       +9     
==========================================
+ Hits         2255     2264       +9     
  Misses        248      248              

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@MateoLostanlen
MateoLostanlen force-pushed the dependabot/uv/main/security-d135905752 branch 2 times, most recently from fb72113 to efe191f Compare May 15, 2026 11:46
passlib 1.7.4 imports bcrypt.__about__ at module load to detect the
bcrypt version. That attribute was removed in bcrypt 4.x, so once
the dependabot bcrypt 5.0.0 bump lands, passlib raises AttributeError
on import and the backend fails its health check at startup.

passlib is effectively unmaintained (last release 2020). Rather than
work around the import, replace the CryptContext usage in
src/app/core/security.py with direct bcrypt calls — the API surface
we use is just hashpw/checkpw plus a salt.

To stay drop-in compatible with hashes generated by the previous
passlib-based code, hash_password / verify_password silently truncate
the password to 72 bytes (bcrypt's hard limit, which passlib used to
swallow) and verify_password catches the ValueError that bcrypt 5.x
now raises on malformed stored hashes, returning False instead — so a
corrupt DB row produces 401, not 500. Both behaviours are covered by
new regression tests in src/tests/test_security.py.
@MateoLostanlen
MateoLostanlen force-pushed the dependabot/uv/main/security-d135905752 branch from efe191f to 4b7908a Compare May 15, 2026 12:09

@MateoLostanlen MateoLostanlen left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving — passlib dropped, bcrypt 5.0 used directly with 72-byte truncation and ValueError catching to match prior passlib semantics. Backward-compatible with existing hashes. Regression tests cover both edge cases. CI 23/23 green.

@MateoLostanlen
MateoLostanlen merged commit 05eec31 into main May 15, 2026
23 checks passed
@MateoLostanlen
MateoLostanlen deleted the dependabot/uv/main/security-d135905752 branch May 15, 2026 12:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ext: tests module: core topic: build Related to build, installation & CI type: misc

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant