Skip to content

release: Buddy2api 2.1.4 cryptography 50.0.1 security bump - #50

Merged
wicm84266964 merged 1 commit into
mainfrom
fix/security-alerts-v2.1.4
Sep 7, 2026
Merged

wicm84266964 merged 1 commit into
mainfrom
fix/security-alerts-v2.1.4

Conversation

@wicm84266964

Copy link
Copy Markdown
Owner

Change

Clear the three GitHub security alerts for 2.1.4.

  • Pin cryptography to 50.0.1 so CVE-2026-69247 (PKCS#7 EnvelopedData Bleichenbacher oracle) is patched. requirements-dev.txt already includes requirements.txt.
  • Document that the QClaw WX_APP_ID is the official public WeChat Open Platform client id, not a secret. The Secret scanning alert was closed as a false positive.
  • Version 2.1.4 with docs/releases/v2.1.4.md.

Validation

  • I ran the repository's documented local checks.

  • I did not add credentials, databases, private account data, or runtime output.

  • I reviewed the changed-file list.

  • I will wait for every required CI check before merging.

  • I did not create or move a release tag in this pull request.

  • python -m compileall -q .

  • python -m pytest -q (245 passed)

  • CI test suite green

  • After merge, run Create release with v2.1.4

Upgrade cryptography to 50.0.1 for CVE-2026-69247. Document that the QClaw WeChat appid is a public OAuth client identifier.
@wicm84266964
wicm84266964 merged commit 03328f5 into main Sep 7, 2026
1 check passed
@wicm84266964
wicm84266964 deleted the fix/security-alerts-v2.1.4 branch September 7, 2026 01:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant