| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Sorry, something went wrong.
There was a problem hiding this comment.
This pull request updates the cryptography dependency requirements in setup.py to use version 41.0.5 or higher for Python 3.14 and above, and introduces a new constraints file constraints-3.14.txt for Python 3.14 testing. Feedback on the changes highlights that setuptools is included in the new constraints file but is missing from the primary dependency specification in setup.py, which violates repository guidelines.
Sorry, something went wrong.
| # Lower-bound constraints for Python 3.14 core dependencies. | ||
| # Pins cryptography==41.0.5 for CPython 3.14 C-extension compatibility. | ||
| pyasn1-modules==0.2.1 | ||
| setuptools==40.3.0 |
There was a problem hiding this comment.
According to the repository's general rules, libraries listed in constraints files must be present in the project's primary dependency specification (e.g., setup.py). setuptools is not listed in the primary DEPENDENCIES of setup.py. Please verify if setuptools should be removed from this constraints file or if it needs to be added to the primary dependency specification.
References
Sorry, something went wrong.
🤖 I have created a release *beep* *boop* --- <details><summary>google-apps-chat: 0.10.2</summary> ## [0.10.2](google-apps-chat-v0.10.1...google-apps-chat-v0.10.2) (2026-07-13) ### Features * update googleapis and regenerate ([#17678](#17678)) ([670917c](670917c)) </details> <details><summary>google-auth: 2.56.0</summary> ## [2.56.0](google-auth-v2.55.2...google-auth-v2.56.0) (2026-07-13) ### Features * **auth:** Implement python mtls helpers ([#17495](#17495)) ([e7baed1](e7baed1)) ### Bug Fixes * **google-auth:** add aiohttp bound for Python 3.14 ([#17654](#17654)) ([b2ec761](b2ec761)) * **google-auth:** add bounds for urllib3 and packaging dependencies ([#17647](#17647)) ([e9c6265](e9c6265)) * **google-auth:** add cryptography bound for Python 3.14 ([#17649](#17649)) ([e9ca4c4](e9ca4c4)) * **google-auth:** add gRPC extra and clean up obsolete TODOs ([#17644](#17644)) ([6da41e8](6da41e8)), closes [#1735](#1735) [#1736](#1736) [#1739](#1739) * **google-auth:** raise rsa extra lower bound to 4.0 ([#17652](#17652)) ([4087828](4087828)) </details> <details><summary>google-cloud-apigee-registry: 0.10.1</summary> ## [0.10.1](google-cloud-apigee-registry-v0.10.0...google-cloud-apigee-registry-v0.10.1) (2026-07-13) ### Features * update googleapis and regenerate ([#17678](#17678)) ([670917c](670917c)) </details> <details><summary>google-cloud-binary-authorization: 1.19.0</summary> ## [1.19.0](google-cloud-binary-authorization-v1.18.0...google-cloud-binary-authorization-v1.19.0) (2026-07-13) ### Features * update googleapis and regenerate ([#17678](#17678)) ([670917c](670917c)) </details> <details><summary>google-cloud-documentai-toolbox: 0.17.1</summary> ## [0.17.1](google-cloud-documentai-toolbox-v0.17.0...google-cloud-documentai-toolbox-v0.17.1) (2026-07-13) ### Bug Fixes * bump jinja2 from 3.1.0 to 3.1.6 in /packages/google-cloud-documentai-toolbox ([#17630](#17630)) ([4cfb931](4cfb931)) * bump pillow from 10.0.0 to 12.2.0 in /packages/google-cloud-documentai-toolbox ([#17631](#17631)) ([1838c35](1838c35)) </details> <details><summary>google-cloud-memorystore: 0.5.2</summary> ## [0.5.2](google-cloud-memorystore-v0.5.1...google-cloud-memorystore-v0.5.2) (2026-07-13) ### Features * update googleapis and regenerate ([#17678](#17678)) ([670917c](670917c)) </details> <details><summary>google-cloud-storage: 3.13.0</summary> ## [3.13.0](google-cloud-storage-v3.12.1...google-cloud-storage-v3.13.0) (2026-07-13) ### Features * **storage:** add option to disable checksums and improve robustness of full_object_checksum validation ([#17665](#17665)) ([a5a717d](a5a717d)) * **storage:** support full_object_checksum in AsyncAppendableObjectWriter ([#17658](#17658)) ([e08d5ca](e08d5ca)) </details> <details><summary>google-devicesandservices-health: 0.1.1</summary> ## [0.1.1](google-devicesandservices-health-v0.1.0...google-devicesandservices-health-v0.1.1) (2026-07-13) ### Features * update googleapis and regenerate ([#17678](#17678)) ([670917c](670917c)) </details> --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com>
| Back | FazBrowse Home | New Git URL |
Summary of Changes
Added "cryptography >= 41.0.5; python_version >= '3.14'" in setup.py and cryptography==41.0.5 in testing/constraints-3.14.txt.
Rationale
In Python 3.14, the legacy setuptools / pkg_resources module was removed from the standard build environment.
Older cryptography versions (< 41.0, including google-auth's default lower bound 38.0.3) utilized pkg_resources in their build hooks. When building from source (sdist) or installing on custom runtimes (such as Alpine Linux, ARM64, or non-manylinux environments), cryptography 38.0.3 fails with a ModuleNotFoundError: No module named 'pkg_resources' build error.
PyCA (Python Cryptography Authority) removed pkg_resources and updated setuptools-rust build hooks in cryptography 41.0.5+.
Setting "cryptography >= 41.0.5; python_version >= '3.14'" ensures:
How to Reproduce
To reproduce the build failure on Python 3.14 without this fix:
pyenv activate py314 pip install --no-binary :all: "cryptography==38.0.3"