Skip to content

⬆️ Update pycryptodome requirement from ~=3.23.0 to ~=3.24.0 - #1103

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/pycryptodome-approx-eq-3.24.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/pycryptodome-approx-eq-3.24.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on pycryptodome to permit the latest version.

Release notes

Sourced from pycryptodome's releases.

v3.24.0 - Evreux

New features

  • Speed up KangarooTwelve by 50% for long messages (1MB or more).
  • New parameter threads for Crypto.Hash.KangarooTwelve.new(), to hash long messages on several CPU cores (threads=0 for all of them). The output does not depend on the number of threads.

Resolved issues

  • GH#875: Fixed the Object Identifiers (OID) for BLAKE2.
  • Fixed a potential DOS attack when decrypting a password-encrypted PKCS#8 key, when the iteration count is enourmous. Decryption will now fail if it exceeds 50M iterations; the limit can be changed or removed via the new max_iteration_count option. Thanks to afldl for reporting.
  • Fixed the maximum number of bytes that GCM should encrypt. Thanks to Loganaden Velvindron.
  • Fixed ECC operations on 32-bit Windows (x86) wheels: due to a compiler bug in Visual Studio 2022, the modular inversion skipped half of the exponent bits, producing wrong results.
  • Fixed a bug in KangarooTwelve in the scenario where customization string is very long (8190 bytes or longer) and the message to hash is empty.

Other changes

  • Build Windows wheel with Visual Studio 2022, from Visual Studio 2019.
  • Remove support for Python 3.7.
Changelog

Sourced from pycryptodome's changelog.

3.24.0 (4 October 2026) ++++++++++++++++++++++++++

New features

  • Speed up KangarooTwelve by 50% for long messages (1MB or more).
  • New parameter threads for Crypto.Hash.KangarooTwelve.new(), to hash long messages on several CPU cores (threads=0 for all of them). The output does not depend on the number of threads.

Resolved issues

  • GH#875: Fixed the Object Identifiers (OID) for BLAKE2.
  • Fixed a potential DOS attack when decrypting a password-encrypted PKCS#8 key, when the iteration count is enourmous. Decryption will now fail if it exceeds 50M iterations; the limit can be changed or removed via the new max_iteration_count option. Thanks to afldl for reporting.
  • Fixed the maximum number of bytes that GCM should encrypt. Thanks to Loganaden Velvindron.
  • Fixed ECC operations on 32-bit Windows (x86) wheels: due to a compiler bug in Visual Studio 2022, the modular inversion skipped half of the exponent bits, producing wrong results.
  • Fixed a bug in KangarooTwelve in the scenario where customization string is very long (8190 bytes or longer) and the message to hash is empty.
  • GH#922: Fixed incorrect verification of an otherwise valid ECDSA signature, when the raw x-coordinate of the computed point is not reduced. Thanks to afldl for reporting and Ville Vesilehto for the fix.

Other changes

  • Build Windows wheel with Visual Studio 2022, from Visual Studio 2019.
  • Remove support for Python 3.7.

3.23.0 (17 May 2025) ++++++++++++++++++++++++++

New features

  • Added cipher modes Key Wrap (KW, RFC3394) and Key Wrap with Padding (KWP, RFC5649). Both are defined also in NIST SP 800-38F.
  • Wheels for Windows ARM.

Resolved issues

  • GH#862: For HashEdDSA and Ed448, sign() and verify() modified the state of the XOF.

3.22.0 (16 March 2025) ++++++++++++++++++++++++++

New features

... (truncated)

Commits
  • a0ed9b6 Bump version
  • b178b48 Use multiple threads for K12
  • ecc840d Further optimization to K12
  • f3cb4e3 Update Changelog
  • 3441382 Fix K12 bug with empty message and long custom string
  • 1552435 Speed up K12
  • 9b5790b Fix for older python versions
  • 77cc653 Update typing stub with _DEFAULT_MAX_ITERATION_COUNT
  • 319f22f Fix max limit of GCM encryption
  • 0336386 Update Changelog
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Updates the requirements on [pycryptodome](https://github.com/Legrandin/pycryptodome) to permit the latest version.
- [Release notes](https://github.com/Legrandin/pycryptodome/releases)
- [Changelog](https://github.com/Legrandin/pycryptodome/blob/master/Changelog.rst)
- [Commits](Legrandin/pycryptodome@v3.23.0...v3.24.0)

---
updated-dependencies:
- dependency-name: pycryptodome
  dependency-version: 3.24.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Oct 7, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants