From 75769102fd2f76fe3932d7e15c850f45b7724826 Mon Sep 17 00:00:00 2001 From: Altynbek Orumbayev Date: Thu, 5 Feb 2026 10:55:23 +0100 Subject: [PATCH 1/3] docs: create a non formal .md file inspired by ADRs in docs Create a non formal .md file providing an analysis of options available to simplify algokit cli distribution to achieve the following: - Complex multi tool distribution pipeline that requires apple developer account, canonical account and dealing with winget which in result only gives the end user a binary that still would not handle python installation for them after they jump into ide where an algokit example or a template has been scaffolded. - Acknowledge that pyinstaller was the most mature thing available at the time of implementing binary mode support but as of 2026 a few alternatives are available. Option A -> go over the codebase check the .github folder check all brew winget and pyinstaller related code including the tests in pytest that only run on pyinstaller binaries. Asses what would need to change if we are to do a switch to https://github.com/aorumbayev/uvget or a system similar to that (a single bash for unix and pwsh for windows - that take care of not just tool install like uvx or uv tool insall put pulling the uv itself and pulling the required python version for algokit to function then install the alogkit from pip). This allows dropping brew winget snap and pipx and simmply provide this single command (along with uv tool install algokit) to everyone. But must be phased so initially uv based installation is introduced and all other installation options moved to legacy and are explicitly marked for removal in next major updated (make the point for we dont have to break and remove what already works instantly). How would we make it smooth for people who had algokit installed via brew winget and etc? Option B. we continue distribution of binaries BUT only via curl with gpg signed executables from gh releases by leveraging https://ofek.dev/pyapp/latest/. This removes brew winget snap but we are still dealing with binaries but pyapp does dynamic python resolution so evaluate if this is fundamentally inferior to the approach with option A. C. Leave it as is and continue distributions of binaries but change default pip installation from pipx to uv tool install Create a laconic, easy to read, easy to approach by engineers working on this codebase document that ouytlines the options for the team to decide in and md file commit that and complete the task --- ...026-02-05_simplify-distribution-options.md | 126 ++++++++++++++++++ 1 file changed, 126 insertions(+) create mode 100644 docs/architecture-decisions/2026-02-05_simplify-distribution-options.md diff --git a/docs/architecture-decisions/2026-02-05_simplify-distribution-options.md b/docs/architecture-decisions/2026-02-05_simplify-distribution-options.md new file mode 100644 index 000000000..e98fc0bdc --- /dev/null +++ b/docs/architecture-decisions/2026-02-05_simplify-distribution-options.md @@ -0,0 +1,126 @@ +# Simplify AlgoKit CLI distribution (2026) + +- **Status:** Draft for discussion +- **Date:** 2026-02-05 +- **Why now:** The current pipeline needs Apple Developer + Canonical + Winget community workflows, and still ships a binary that does not help users get Python when they open a template in an IDE. PyInstaller was the most mature choice at the time, but by 2026 there are solid alternatives. + +## Goal + +- Reduce distribution surface area and account overhead. +- Make installs handle Python for users. +- Keep migration non-disruptive for existing users. + +## Current moving parts (just enough map) + +- Build + publish binaries: `.github/workflows/build-binaries.yaml`, `.github/actions/build-binaries/*`, `.github/workflows/publish-release-packages.yaml`. +- PyInstaller packaging: `pyproject.toml` (`package_*` tasks + dependency), `scripts/package_mac.sh`, `scripts/package_windows.bat`. +- Channel scripts: `scripts/update-brew-cask.sh`, `scripts/snap/create-snapcraft-yaml.sh`, `scripts/winget/*`. +- PyInstaller-only tests: `tests/portability/test_pyinstaller_binary.py`, `pyproject.toml` marker `pyinstaller_binary_tests`. +- Update hints: `src/algokit/core/config_commands/version_prompt.py` (distribution-method + update command). +- Install/tool checks: `src/algokit/cli/doctor.py` (pipx/brew/winget). +- Docs: `README.md`, `docs/tutorials/intro.md`, `docs/features/*`. + +## Alternatives that exist now (2026) + +- `pyapp` (https://ofek.dev/pyapp/latest/) for dynamic Python resolution in binaries. +- `uvget`-style installers (https://github.com/aorumbayev/uvget) to bootstrap uv + Python + tool install. +- Other packaging options: Nuitka, PEX, Shiv (less relevant if we stop shipping binaries). + +## Option A: uvget-style installer + `uv tool install algokit` + +Single bash + pwsh entrypoint that fetches uv, pulls Python 3.12, then installs AlgoKit with `uv tool install`. This becomes the default path; brew/winget/snap stay but are marked legacy and removed next major. + +```mermaid +flowchart TD + U[User] --> I["Universal installer
bash / pwsh"] + I --> UV["Install uv"] + UV --> PY["Install Python 3.12"] + PY --> A["uv tool install algokit"] + A --> CLI["algokit (uv-managed)"] + L[Legacy channels
brew/winget/snap] -->|phase out| X["Removed next major"] +``` + +**What changes (codebase impact)** + +- CI/CD: add a job that publishes installer scripts + checksums/signatures; keep `build-binaries` + `publish-release-packages` during the legacy period, then remove in the next major. +- Packaging: remove `pyinstaller` from `pyproject.toml` and drop `package_*` tasks after the legacy period; retire `scripts/package_*` at the same time. +- Channels: remove/retire `scripts/update-brew-cask.sh`, `scripts/snap/*`, `scripts/winget/*` once legacy period ends. +- Runtime hints: update `src/algokit/core/config_commands/version_prompt.py` to include `uv` update guidance (and add a new distribution-method for `uv` installs). +- Doctor + docs: update `src/algokit/cli/doctor.py`, `README.md`, `docs/tutorials/intro.md`, `docs/features/*` to prefer uv and mark brew/winget/snap as legacy. +- Tests: replace `tests/portability/test_pyinstaller_binary.py` with installer smoke tests (e.g., run the script, verify `algokit doctor` / `algokit init`). +- Internal tool resolution: migrate pipx-based helpers (typed client generation, compiler installs, tealer install, poetry bootstrap) to uv equivalents (`uv tool run` / `uvx`). +- CLI update command: add `algokit update` behind a feature flag. Initially no-op or hidden; once binaries are removed, it becomes the default update path and runs `uv tool upgrade algokit`. If a legacy binary install is detected (via binary mode + distribution-method), it can launch a migration wizard on startup that points to the universal installer script and offers to install the legacy version first (nice to have). + +**Smooth migration for existing brew/winget/snap users** + +- Phase 1: keep publishing binaries, but add a deprecation note in docs + release notes + `algokit doctor` output for those distribution methods. +- Phase 2: add explicit upgrade guidance in CLI (`algokit version-prompt` message for brew/winget/snap users pointing at the new install command). +- Phase 3 (next major): stop new package manager releases, keep uninstall guidance; optionally publish a last “bridge” release that only shows the migration message. + +**Pros** + +- One installer path, fewer accounts and CI steps. +- Solves “binary but no Python in IDE” by owning Python install. +- Easier to support consistent behavior across OSes. + +**Cons** + +- Requires trust in a bootstrap script + network access. +- Adds uv as a required bootstrap dependency. +- Needs careful messaging to avoid churn for existing users. + +## Option B: keep binaries, move to `pyapp` + curl + GPG-signed releases + +Drop brew/winget/snap; ship signed binaries via GH releases and a curl-based installer. `pyapp` handles Python resolution at runtime. + +```mermaid +flowchart TD + R[Release] --> B["Build per-OS binaries"] + B --> S["Codesign + GPG sign"] + S --> GH["GitHub Releases"] + U[User] --> C["curl install script"] + C --> GH + C --> P["pyapp resolves Python"] + P --> CLI["algokit (binary)"] +``` + +**Pros** + +- Fewer distribution channels and less package manager overhead. +- Python resolution is handled by `pyapp` (better than today’s binaries). + +**Cons** + +- Still a binary pipeline; still per-OS builds and likely code signing on macOS. +- Update experience is still manual unless we build a self-update story. +- Might still be less flexible than uv-driven installs for toolchain workflows. + +## Option C: keep current binaries, switch pipx to `uv tool install` + +Leave distribution as-is, but move pip-based installs from pipx to uv. This is the smallest change. + +```mermaid +flowchart TD + R[Release] --> B["Build pyinstaller binaries"] + B --> CH["brew / winget / snap"] + U[User] --> CH + U --> P["uv tool install (pip path)"] + P --> CLI["algokit (pip/uv)"] + CH --> CLI2["algokit (binary)"] +``` + +**What changes** + +- Update `src/algokit/core/utils.py` + call sites that use pipx for tool resolution (typed client generation, compiler install, tealer install, poetry bootstrap). +- Update tests and docs that reference pipx (e.g., `docs/features/compile.md`, `docs/features/generate.md`, `README.md`). + +**Trade-off** + +- Low effort; does not reduce distribution complexity or account needs. +- Still leaves “binary install doesn’t manage Python” unaddressed. + +## Notes / open questions + +- Python pin: target Python 3.12 for the uv-based install. +- Installer scope: limit to AlgoKit CLI + Python only. Project dependencies are handled via `algokit init` + bootstrap; that flow can install some tools (e.g., Poetry) but still assumes system prerequisites like Node and Docker (see `docs/features/init.md`, `docs/features/project/bootstrap.md`). +- Remaining question: hard EOL date for brew/winget/snap vs keep as best effort? From 2c7aaf83bb8f0342ea2c2f4878a993af3ad8d7d7 Mon Sep 17 00:00:00 2001 From: Altynbek Orumbayev Date: Thu, 5 Feb 2026 11:04:43 +0100 Subject: [PATCH 2/3] chore: note npm --- .../2026-02-05_simplify-distribution-options.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/docs/architecture-decisions/2026-02-05_simplify-distribution-options.md b/docs/architecture-decisions/2026-02-05_simplify-distribution-options.md index e98fc0bdc..ea10c5682 100644 --- a/docs/architecture-decisions/2026-02-05_simplify-distribution-options.md +++ b/docs/architecture-decisions/2026-02-05_simplify-distribution-options.md @@ -37,6 +37,7 @@ flowchart TD UV --> PY["Install Python 3.12"] PY --> A["uv tool install algokit"] A --> CLI["algokit (uv-managed)"] + NPM["npm wrapper (nice to have)"] --> I L[Legacy channels
brew/winget/snap] -->|phase out| X["Removed next major"] ``` @@ -50,6 +51,7 @@ flowchart TD - Tests: replace `tests/portability/test_pyinstaller_binary.py` with installer smoke tests (e.g., run the script, verify `algokit doctor` / `algokit init`). - Internal tool resolution: migrate pipx-based helpers (typed client generation, compiler installs, tealer install, poetry bootstrap) to uv equivalents (`uv tool run` / `uvx`). - CLI update command: add `algokit update` behind a feature flag. Initially no-op or hidden; once binaries are removed, it becomes the default update path and runs `uv tool upgrade algokit`. If a legacy binary install is detected (via binary mode + distribution-method), it can launch a migration wizard on startup that points to the universal installer script and offers to install the legacy version first (nice to have). +- npm channel: publish a small npm wrapper that invokes the universal installer (nice to have, easy once Option A exists). **Smooth migration for existing brew/winget/snap users** From 2324663613c5d923fc38eafd713943933844edea Mon Sep 17 00:00:00 2001 From: Altynbek Orumbayev Date: Wed, 25 Feb 2026 16:44:53 +0100 Subject: [PATCH 3/3] docs: mark uv distribution ADR as decided (Option A); fix cryptography vulnerability --- ...026-02-05_simplify-distribution-options.md | 2 +- poetry.lock | 113 ++++++++++-------- pyproject.toml | 2 +- 3 files changed, 65 insertions(+), 52 deletions(-) diff --git a/docs/architecture-decisions/2026-02-05_simplify-distribution-options.md b/docs/architecture-decisions/2026-02-05_simplify-distribution-options.md index ea10c5682..850764683 100644 --- a/docs/architecture-decisions/2026-02-05_simplify-distribution-options.md +++ b/docs/architecture-decisions/2026-02-05_simplify-distribution-options.md @@ -1,6 +1,6 @@ # Simplify AlgoKit CLI distribution (2026) -- **Status:** Draft for discussion +- **Status:** Decided — Option A (uvget-style installer + `uv tool install algokit`) - **Date:** 2026-02-05 - **Why now:** The current pipeline needs Apple Developer + Canonical + Winget community workflows, and still ships a binary that does not help users get Python when they open a template in an IDE. PyInstaller was the most mature choice at the time, but by 2026 there are solid alternatives. diff --git a/poetry.lock b/poetry.lock index de1a9a67a..8507f5085 100644 --- a/poetry.lock +++ b/poetry.lock @@ -614,62 +614,75 @@ toml = ["tomli ; python_full_version <= \"3.11.0a6\""] [[package]] name = "cryptography" -version = "44.0.3" +version = "46.0.5" description = "cryptography is a package which provides cryptographic recipes and primitives to Python developers." optional = false -python-versions = "!=3.9.0,!=3.9.1,>=3.7" +python-versions = "!=3.9.0,!=3.9.1,>=3.8" groups = ["main", "dev"] files = [ - {file = "cryptography-44.0.3-cp37-abi3-macosx_10_9_universal2.whl", hash = "sha256:962bc30480a08d133e631e8dfd4783ab71cc9e33d5d7c1e192f0b7c06397bb88"}, - {file = "cryptography-44.0.3-cp37-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl", hash = "sha256:4ffc61e8f3bf5b60346d89cd3d37231019c17a081208dfbbd6e1605ba03fa137"}, - {file = "cryptography-44.0.3-cp37-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl", hash = "sha256:58968d331425a6f9eedcee087f77fd3c927c88f55368f43ff7e0a19891f2642c"}, - {file = "cryptography-44.0.3-cp37-abi3-manylinux_2_28_aarch64.whl", hash = "sha256:e28d62e59a4dbd1d22e747f57d4f00c459af22181f0b2f787ea83f5a876d7c76"}, - {file = "cryptography-44.0.3-cp37-abi3-manylinux_2_28_armv7l.manylinux_2_31_armv7l.whl", hash = "sha256:af653022a0c25ef2e3ffb2c673a50e5a0d02fecc41608f4954176f1933b12359"}, - {file = "cryptography-44.0.3-cp37-abi3-manylinux_2_28_x86_64.whl", hash = "sha256:157f1f3b8d941c2bd8f3ffee0af9b049c9665c39d3da9db2dc338feca5e98a43"}, - {file = "cryptography-44.0.3-cp37-abi3-manylinux_2_34_aarch64.whl", hash = "sha256:c6cd67722619e4d55fdb42ead64ed8843d64638e9c07f4011163e46bc512cf01"}, - {file = "cryptography-44.0.3-cp37-abi3-manylinux_2_34_x86_64.whl", hash = "sha256:b424563394c369a804ecbee9b06dfb34997f19d00b3518e39f83a5642618397d"}, - {file = "cryptography-44.0.3-cp37-abi3-musllinux_1_2_aarch64.whl", hash = "sha256:c91fc8e8fd78af553f98bc7f2a1d8db977334e4eea302a4bfd75b9461c2d8904"}, - {file = "cryptography-44.0.3-cp37-abi3-musllinux_1_2_x86_64.whl", hash = "sha256:25cd194c39fa5a0aa4169125ee27d1172097857b27109a45fadc59653ec06f44"}, - {file = "cryptography-44.0.3-cp37-abi3-win32.whl", hash = "sha256:3be3f649d91cb182c3a6bd336de8b61a0a71965bd13d1a04a0e15b39c3d5809d"}, - {file = "cryptography-44.0.3-cp37-abi3-win_amd64.whl", hash = "sha256:3883076d5c4cc56dbef0b898a74eb6992fdac29a7b9013870b34efe4ddb39a0d"}, - {file = "cryptography-44.0.3-cp39-abi3-macosx_10_9_universal2.whl", hash = "sha256:5639c2b16764c6f76eedf722dbad9a0914960d3489c0cc38694ddf9464f1bb2f"}, - {file = "cryptography-44.0.3-cp39-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl", hash = "sha256:f3ffef566ac88f75967d7abd852ed5f182da252d23fac11b4766da3957766759"}, - {file = "cryptography-44.0.3-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl", hash = "sha256:192ed30fac1728f7587c6f4613c29c584abdc565d7417c13904708db10206645"}, - {file = "cryptography-44.0.3-cp39-abi3-manylinux_2_28_aarch64.whl", hash = "sha256:7d5fe7195c27c32a64955740b949070f21cba664604291c298518d2e255931d2"}, - {file = "cryptography-44.0.3-cp39-abi3-manylinux_2_28_armv7l.manylinux_2_31_armv7l.whl", hash = "sha256:3f07943aa4d7dad689e3bb1638ddc4944cc5e0921e3c227486daae0e31a05e54"}, - {file = "cryptography-44.0.3-cp39-abi3-manylinux_2_28_x86_64.whl", hash = "sha256:cb90f60e03d563ca2445099edf605c16ed1d5b15182d21831f58460c48bffb93"}, - {file = "cryptography-44.0.3-cp39-abi3-manylinux_2_34_aarch64.whl", hash = "sha256:ab0b005721cc0039e885ac3503825661bd9810b15d4f374e473f8c89b7d5460c"}, - {file = "cryptography-44.0.3-cp39-abi3-manylinux_2_34_x86_64.whl", hash = "sha256:3bb0847e6363c037df8f6ede57d88eaf3410ca2267fb12275370a76f85786a6f"}, - {file = "cryptography-44.0.3-cp39-abi3-musllinux_1_2_aarch64.whl", hash = "sha256:b0cc66c74c797e1db750aaa842ad5b8b78e14805a9b5d1348dc603612d3e3ff5"}, - {file = "cryptography-44.0.3-cp39-abi3-musllinux_1_2_x86_64.whl", hash = "sha256:6866df152b581f9429020320e5eb9794c8780e90f7ccb021940d7f50ee00ae0b"}, - {file = "cryptography-44.0.3-cp39-abi3-win32.whl", hash = "sha256:c138abae3a12a94c75c10499f1cbae81294a6f983b3af066390adee73f433028"}, - {file = "cryptography-44.0.3-cp39-abi3-win_amd64.whl", hash = "sha256:5d186f32e52e66994dce4f766884bcb9c68b8da62d61d9d215bfe5fb56d21334"}, - {file = "cryptography-44.0.3-pp310-pypy310_pp73-macosx_10_9_x86_64.whl", hash = "sha256:cad399780053fb383dc067475135e41c9fe7d901a97dd5d9c5dfb5611afc0d7d"}, - {file = "cryptography-44.0.3-pp310-pypy310_pp73-manylinux_2_28_aarch64.whl", hash = "sha256:21a83f6f35b9cc656d71b5de8d519f566df01e660ac2578805ab245ffd8523f8"}, - {file = "cryptography-44.0.3-pp310-pypy310_pp73-manylinux_2_28_x86_64.whl", hash = "sha256:fc3c9babc1e1faefd62704bb46a69f359a9819eb0292e40df3fb6e3574715cd4"}, - {file = "cryptography-44.0.3-pp310-pypy310_pp73-manylinux_2_34_aarch64.whl", hash = "sha256:e909df4053064a97f1e6565153ff8bb389af12c5c8d29c343308760890560aff"}, - {file = "cryptography-44.0.3-pp310-pypy310_pp73-manylinux_2_34_x86_64.whl", hash = "sha256:dad80b45c22e05b259e33ddd458e9e2ba099c86ccf4e88db7bbab4b747b18d06"}, - {file = "cryptography-44.0.3-pp310-pypy310_pp73-win_amd64.whl", hash = "sha256:479d92908277bed6e1a1c69b277734a7771c2b78633c224445b5c60a9f4bc1d9"}, - {file = "cryptography-44.0.3-pp311-pypy311_pp73-macosx_10_9_x86_64.whl", hash = "sha256:896530bc9107b226f265effa7ef3f21270f18a2026bc09fed1ebd7b66ddf6375"}, - {file = "cryptography-44.0.3-pp311-pypy311_pp73-manylinux_2_28_aarch64.whl", hash = "sha256:9b4d4a5dbee05a2c390bf212e78b99434efec37b17a4bff42f50285c5c8c9647"}, - {file = "cryptography-44.0.3-pp311-pypy311_pp73-manylinux_2_28_x86_64.whl", hash = "sha256:02f55fb4f8b79c1221b0961488eaae21015b69b210e18c386b69de182ebb1259"}, - {file = "cryptography-44.0.3-pp311-pypy311_pp73-manylinux_2_34_aarch64.whl", hash = "sha256:dd3db61b8fe5be220eee484a17233287d0be6932d056cf5738225b9c05ef4fff"}, - {file = "cryptography-44.0.3-pp311-pypy311_pp73-manylinux_2_34_x86_64.whl", hash = "sha256:978631ec51a6bbc0b7e58f23b68a8ce9e5f09721940933e9c217068388789fe5"}, - {file = "cryptography-44.0.3-pp311-pypy311_pp73-win_amd64.whl", hash = "sha256:5d20cc348cca3a8aa7312f42ab953a56e15323800ca3ab0706b8cd452a3a056c"}, - {file = "cryptography-44.0.3.tar.gz", hash = "sha256:fe19d8bc5536a91a24a8133328880a41831b6c5df54599a8417b62fe015d3053"}, -] - -[package.dependencies] -cffi = {version = ">=1.12", markers = "platform_python_implementation != \"PyPy\""} - -[package.extras] -docs = ["sphinx (>=5.3.0)", "sphinx-rtd-theme (>=3.0.0) ; python_version >= \"3.8\""] + {file = "cryptography-46.0.5-cp311-abi3-macosx_10_9_universal2.whl", hash = "sha256:351695ada9ea9618b3500b490ad54c739860883df6c1f555e088eaf25b1bbaad"}, + {file = "cryptography-46.0.5-cp311-abi3-manylinux2014_aarch64.manylinux_2_17_aarch64.whl", hash = "sha256:c18ff11e86df2e28854939acde2d003f7984f721eba450b56a200ad90eeb0e6b"}, + {file = "cryptography-46.0.5-cp311-abi3-manylinux2014_x86_64.manylinux_2_17_x86_64.whl", hash = "sha256:4d7e3d356b8cd4ea5aff04f129d5f66ebdc7b6f8eae802b93739ed520c47c79b"}, + {file = "cryptography-46.0.5-cp311-abi3-manylinux_2_28_aarch64.whl", hash = "sha256:50bfb6925eff619c9c023b967d5b77a54e04256c4281b0e21336a130cd7fc263"}, + {file = "cryptography-46.0.5-cp311-abi3-manylinux_2_28_ppc64le.whl", hash = "sha256:803812e111e75d1aa73690d2facc295eaefd4439be1023fefc4995eaea2af90d"}, + {file = "cryptography-46.0.5-cp311-abi3-manylinux_2_28_x86_64.whl", hash = "sha256:3ee190460e2fbe447175cda91b88b84ae8322a104fc27766ad09428754a618ed"}, + {file = "cryptography-46.0.5-cp311-abi3-manylinux_2_31_armv7l.whl", hash = "sha256:f145bba11b878005c496e93e257c1e88f154d278d2638e6450d17e0f31e558d2"}, + {file = "cryptography-46.0.5-cp311-abi3-manylinux_2_34_aarch64.whl", hash = "sha256:e9251e3be159d1020c4030bd2e5f84d6a43fe54b6c19c12f51cde9542a2817b2"}, + {file = "cryptography-46.0.5-cp311-abi3-manylinux_2_34_ppc64le.whl", hash = "sha256:47fb8a66058b80e509c47118ef8a75d14c455e81ac369050f20ba0d23e77fee0"}, + {file = "cryptography-46.0.5-cp311-abi3-manylinux_2_34_x86_64.whl", hash = "sha256:4c3341037c136030cb46e4b1e17b7418ea4cbd9dd207e4a6f3b2b24e0d4ac731"}, + {file = "cryptography-46.0.5-cp311-abi3-musllinux_1_2_aarch64.whl", hash = "sha256:890bcb4abd5a2d3f852196437129eb3667d62630333aacc13dfd470fad3aaa82"}, + {file = "cryptography-46.0.5-cp311-abi3-musllinux_1_2_x86_64.whl", hash = "sha256:80a8d7bfdf38f87ca30a5391c0c9ce4ed2926918e017c29ddf643d0ed2778ea1"}, + {file = "cryptography-46.0.5-cp311-abi3-win32.whl", hash = "sha256:60ee7e19e95104d4c03871d7d7dfb3d22ef8a9b9c6778c94e1c8fcc8365afd48"}, + {file = "cryptography-46.0.5-cp311-abi3-win_amd64.whl", hash = "sha256:38946c54b16c885c72c4f59846be9743d699eee2b69b6988e0a00a01f46a61a4"}, + {file = "cryptography-46.0.5-cp314-cp314t-macosx_10_9_universal2.whl", hash = "sha256:94a76daa32eb78d61339aff7952ea819b1734b46f73646a07decb40e5b3448e2"}, + {file = "cryptography-46.0.5-cp314-cp314t-manylinux2014_aarch64.manylinux_2_17_aarch64.whl", hash = "sha256:5be7bf2fb40769e05739dd0046e7b26f9d4670badc7b032d6ce4db64dddc0678"}, + {file = "cryptography-46.0.5-cp314-cp314t-manylinux2014_x86_64.manylinux_2_17_x86_64.whl", hash = "sha256:fe346b143ff9685e40192a4960938545c699054ba11d4f9029f94751e3f71d87"}, + {file = "cryptography-46.0.5-cp314-cp314t-manylinux_2_28_aarch64.whl", hash = "sha256:c69fd885df7d089548a42d5ec05be26050ebcd2283d89b3d30676eb32ff87dee"}, + {file = "cryptography-46.0.5-cp314-cp314t-manylinux_2_28_ppc64le.whl", hash = "sha256:8293f3dea7fc929ef7240796ba231413afa7b68ce38fd21da2995549f5961981"}, + {file = "cryptography-46.0.5-cp314-cp314t-manylinux_2_28_x86_64.whl", hash = "sha256:1abfdb89b41c3be0365328a410baa9df3ff8a9110fb75e7b52e66803ddabc9a9"}, + {file = "cryptography-46.0.5-cp314-cp314t-manylinux_2_31_armv7l.whl", hash = "sha256:d66e421495fdb797610a08f43b05269e0a5ea7f5e652a89bfd5a7d3c1dee3648"}, + {file = "cryptography-46.0.5-cp314-cp314t-manylinux_2_34_aarch64.whl", hash = "sha256:4e817a8920bfbcff8940ecfd60f23d01836408242b30f1a708d93198393a80b4"}, + {file = "cryptography-46.0.5-cp314-cp314t-manylinux_2_34_ppc64le.whl", hash = "sha256:68f68d13f2e1cb95163fa3b4db4bf9a159a418f5f6e7242564fc75fcae667fd0"}, + {file = "cryptography-46.0.5-cp314-cp314t-manylinux_2_34_x86_64.whl", hash = "sha256:a3d1fae9863299076f05cb8a778c467578262fae09f9dc0ee9b12eb4268ce663"}, + {file = "cryptography-46.0.5-cp314-cp314t-musllinux_1_2_aarch64.whl", hash = "sha256:c4143987a42a2397f2fc3b4d7e3a7d313fbe684f67ff443999e803dd75a76826"}, + {file = "cryptography-46.0.5-cp314-cp314t-musllinux_1_2_x86_64.whl", hash = "sha256:7d731d4b107030987fd61a7f8ab512b25b53cef8f233a97379ede116f30eb67d"}, + {file = "cryptography-46.0.5-cp314-cp314t-win32.whl", hash = "sha256:c3bcce8521d785d510b2aad26ae2c966092b7daa8f45dd8f44734a104dc0bc1a"}, + {file = "cryptography-46.0.5-cp314-cp314t-win_amd64.whl", hash = "sha256:4d8ae8659ab18c65ced284993c2265910f6c9e650189d4e3f68445ef82a810e4"}, + {file = "cryptography-46.0.5-cp38-abi3-macosx_10_9_universal2.whl", hash = "sha256:4108d4c09fbbf2789d0c926eb4152ae1760d5a2d97612b92d508d96c861e4d31"}, + {file = "cryptography-46.0.5-cp38-abi3-manylinux2014_aarch64.manylinux_2_17_aarch64.whl", hash = "sha256:7d1f30a86d2757199cb2d56e48cce14deddf1f9c95f1ef1b64ee91ea43fe2e18"}, + {file = "cryptography-46.0.5-cp38-abi3-manylinux2014_x86_64.manylinux_2_17_x86_64.whl", hash = "sha256:039917b0dc418bb9f6edce8a906572d69e74bd330b0b3fea4f79dab7f8ddd235"}, + {file = "cryptography-46.0.5-cp38-abi3-manylinux_2_28_aarch64.whl", hash = "sha256:ba2a27ff02f48193fc4daeadf8ad2590516fa3d0adeeb34336b96f7fa64c1e3a"}, + {file = "cryptography-46.0.5-cp38-abi3-manylinux_2_28_ppc64le.whl", hash = "sha256:61aa400dce22cb001a98014f647dc21cda08f7915ceb95df0c9eaf84b4b6af76"}, + {file = "cryptography-46.0.5-cp38-abi3-manylinux_2_28_x86_64.whl", hash = "sha256:3ce58ba46e1bc2aac4f7d9290223cead56743fa6ab94a5d53292ffaac6a91614"}, + {file = "cryptography-46.0.5-cp38-abi3-manylinux_2_31_armv7l.whl", hash = "sha256:420d0e909050490d04359e7fdb5ed7e667ca5c3c402b809ae2563d7e66a92229"}, + {file = "cryptography-46.0.5-cp38-abi3-manylinux_2_34_aarch64.whl", hash = "sha256:582f5fcd2afa31622f317f80426a027f30dc792e9c80ffee87b993200ea115f1"}, + {file = "cryptography-46.0.5-cp38-abi3-manylinux_2_34_ppc64le.whl", hash = "sha256:bfd56bb4b37ed4f330b82402f6f435845a5f5648edf1ad497da51a8452d5d62d"}, + {file = "cryptography-46.0.5-cp38-abi3-manylinux_2_34_x86_64.whl", hash = "sha256:a3d507bb6a513ca96ba84443226af944b0f7f47dcc9a399d110cd6146481d24c"}, + {file = "cryptography-46.0.5-cp38-abi3-musllinux_1_2_aarch64.whl", hash = "sha256:9f16fbdf4da055efb21c22d81b89f155f02ba420558db21288b3d0035bafd5f4"}, + {file = "cryptography-46.0.5-cp38-abi3-musllinux_1_2_x86_64.whl", hash = "sha256:ced80795227d70549a411a4ab66e8ce307899fad2220ce5ab2f296e687eacde9"}, + {file = "cryptography-46.0.5-cp38-abi3-win32.whl", hash = "sha256:02f547fce831f5096c9a567fd41bc12ca8f11df260959ecc7c3202555cc47a72"}, + {file = "cryptography-46.0.5-cp38-abi3-win_amd64.whl", hash = "sha256:556e106ee01aa13484ce9b0239bca667be5004efb0aabbed28d353df86445595"}, + {file = "cryptography-46.0.5-pp311-pypy311_pp73-macosx_11_0_arm64.whl", hash = "sha256:3b4995dc971c9fb83c25aa44cf45f02ba86f71ee600d81091c2f0cbae116b06c"}, + {file = "cryptography-46.0.5-pp311-pypy311_pp73-manylinux_2_28_aarch64.whl", hash = "sha256:bc84e875994c3b445871ea7181d424588171efec3e185dced958dad9e001950a"}, + {file = "cryptography-46.0.5-pp311-pypy311_pp73-manylinux_2_28_x86_64.whl", hash = "sha256:2ae6971afd6246710480e3f15824ed3029a60fc16991db250034efd0b9fb4356"}, + {file = "cryptography-46.0.5-pp311-pypy311_pp73-manylinux_2_34_aarch64.whl", hash = "sha256:d861ee9e76ace6cf36a6a89b959ec08e7bc2493ee39d07ffe5acb23ef46d27da"}, + {file = "cryptography-46.0.5-pp311-pypy311_pp73-manylinux_2_34_x86_64.whl", hash = "sha256:2b7a67c9cd56372f3249b39699f2ad479f6991e62ea15800973b956f4b73e257"}, + {file = "cryptography-46.0.5-pp311-pypy311_pp73-win_amd64.whl", hash = "sha256:8456928655f856c6e1533ff59d5be76578a7157224dbd9ce6872f25055ab9ab7"}, + {file = "cryptography-46.0.5.tar.gz", hash = "sha256:abace499247268e3757271b2f1e244b36b06f8515cf27c4d49468fc9eb16e93d"}, +] + +[package.dependencies] +cffi = {version = ">=2.0.0", markers = "python_full_version >= \"3.9.0\" and platform_python_implementation != \"PyPy\""} +typing-extensions = {version = ">=4.13.2", markers = "python_full_version < \"3.11.0\""} + +[package.extras] +docs = ["sphinx (>=5.3.0)", "sphinx-inline-tabs", "sphinx-rtd-theme (>=3.0.0)"] docstest = ["pyenchant (>=3)", "readme-renderer (>=30.0)", "sphinxcontrib-spelling (>=7.3.1)"] -nox = ["nox (>=2024.4.15)", "nox[uv] (>=2024.3.2) ; python_version >= \"3.8\""] -pep8test = ["check-sdist ; python_version >= \"3.8\"", "click (>=8.0.1)", "mypy (>=1.4)", "ruff (>=0.3.6)"] +nox = ["nox[uv] (>=2024.4.15)"] +pep8test = ["check-sdist", "click (>=8.0.1)", "mypy (>=1.14)", "ruff (>=0.11.11)"] sdist = ["build (>=1.0.0)"] ssh = ["bcrypt (>=3.1.5)"] -test = ["certifi (>=2024)", "cryptography-vectors (==44.0.3)", "pretend (>=0.7)", "pytest (>=7.4.0)", "pytest-benchmark (>=4.0)", "pytest-cov (>=2.10.1)", "pytest-xdist (>=3.5.0)"] +test = ["certifi (>=2024)", "cryptography-vectors (==46.0.5)", "pretend (>=0.7)", "pytest (>=7.4.0)", "pytest-benchmark (>=4.0)", "pytest-cov (>=2.10.1)", "pytest-xdist (>=3.5.0)"] test-randomorder = ["pytest-randomly"] [[package]] @@ -3456,4 +3469,4 @@ type = ["pytest-mypy"] [metadata] lock-version = "2.1" python-versions = ">=3.10,<3.15" -content-hash = "1aafa2e9f1424c37ee9138f4674f333b5d42ecec3c50077fc92fd7cc7d87c5d3" +content-hash = "768fd47a97eb57d798f690c838b21841bfce80878ba19d959db7e07b78a5a18c" diff --git a/pyproject.toml b/pyproject.toml index 5af926c44..a6b4856c3 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -23,7 +23,7 @@ keyring = "25.6.0" # see header in src/algokit/core/_vendor/auth0/authentication/token_verifier.py # this version has been tested to work with the vendored file pyjwt = "^2.10.1" -cryptography = "^44.0.2" # pyjwt has a weak dependency on cryptography and explicitly requires it in the vendored file, hence the lock +cryptography = "^46.0.5" # pyjwt has a weak dependency on cryptography and explicitly requires it in the vendored file, hence the lock algokit-utils = "^4.0.1" multiformats = "0.3.1" multiformats_config = "0.3.1" # pinned this to be in lockstep with multiformats