Skip to content

Python dependency: Bump paramiko from 3.5.1 to 5.0.0#9927

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/paramiko-5.0.0
Open

Python dependency: Bump paramiko from 3.5.1 to 5.0.0#9927
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/paramiko-5.0.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 11, 2026

Bumps paramiko from 3.5.1 to 5.0.0.

Commits
  • 710cc5c What's a few weeks between friends?
  • ea93c59 Fix up Ed25519Key so it has non-erroring repr() during fatal errors
  • 5b90ef9 ruff/isort
  • f3864b6 Changelog fixes
  • acd4bc1 Replace hardcoded PEM format in PKey.write* with new parameter
  • 6fa1556 Bump group-exchange kex min_bits to 2048
  • eb87ad3 Fix some tests that were incorrectly passing
  • 1ecc933 Remove GSSAPI support :(
  • 9bf5fca Remove SHA1-based (non-GSS) kex methods
  • b8f75c7 Lintin' ain't easy
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [paramiko](https://github.com/paramiko/paramiko) from 3.5.1 to 5.0.0.
- [Commits](paramiko/paramiko@3.5.1...5.0.0)

---
updated-dependencies:
- dependency-name: paramiko
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the Dependencies Pull requests that update a dependency file label May 11, 2026
asheshv added a commit that referenced this pull request May 20, 2026
…#9954)

Python:
- requirements.txt: google-auth-oauthlib 1.3.1 -> 1.4.0
  (#9929 / #9931), gated so Python 3.9 stays on 1.3.1 (1.4.0
  requires python_version >= 3.10). Mirrors the existing
  boto3 1.42.*/1.43.* split.
- tools/requirements.txt: requests >=2.33.1 -> >=2.34.2 on
  python_version > '3.9' (#9943 / #9944).
- web/regression/requirements.txt: selenium 4.43.0 -> 4.44.0
  (#9946). The selenium pin already requires Python >=3.10 in
  master, so the bump introduces no new 3.9 gap.

JavaScript (web/package.json, web/yarn.lock):
- postcss 8.5.12 -> 8.5.14 (#9874 / #9889)
- @tanstack/react-query 5.100.5 -> 5.100.9 (#9878)
- ip-address 10.1.0 -> 10.1.1 (#9918)
- packageManager pin yarn@4.14.0 -> yarn@4.15.0 and regenerate
  yarn.lock at lockfile __metadata.version 10. CI runs yarn
  4.15.0 with hardened mode on public PRs and refuses to migrate
  the lockfile from version 9 (yarn 4.14.x) to 10; master passes
  today only because hardened mode is PR-only.

Electron runtime (runtime/package.json, runtime/yarn.lock):
- axios 1.16.0 -> 1.16.1 (#9948)
- eslint 10.3.0 -> 10.4.0 (#9947)

Skipped (genuine breaking changes, deferred to follow-up PRs):
- @mui/material 7 -> 9 (#9843)
- @mui/x-date-pickers 8 -> 9 (#9888)
- cryptography 47.0.* -> 48.0.* (#9926 / #9932)
- paramiko 3.5.1 -> 5.0.0 (#9927 / #9930)
- electron 41.5.0 -> 42.1.0 (#9945)

Verified in an isolated worktree:

  - jest:        140/0/0 suites, 824/0/0 tests
  - eslint:      clean (web + runtime, both silent)
  - pycodestyle: 0 violations project-wide

Each version was cross-checked against the corresponding
dependabot PR diff via `gh pr diff`. Each Python bump was
cross-checked against PyPI's requires_python so Python 3.9
support stays intact.
@asheshv
Copy link
Copy Markdown
Contributor

asheshv commented May 20, 2026

Audited on 2026-05-20 and intentionally deferred for now (re-evaluate ~Q4 2026). Leaving this PR open as a tracking item.

Why deferred — short version

paramiko 5 is not blocked by the GSSAPI removal that initial review flagged. pgAdmin's SSH tunnel only offers password + identity-file auth (web/pgadmin/utils/driver/psycopg3/server_manager.py:590-608); GSSAPI is not exposed as an SSH-tunnel auth method. The gssapi==1.11.* dependency in requirements.txt is for pgAdmin's own web-login Kerberos authentication (web/pgadmin/authenticate/webserver.py), which is an entirely separate code path.

The real concern is legacy SSH bastion compatibility. paramiko 5 removed:

  • SHA1-based KEX methods (diffie-hellman-group1-sha1, diffie-hellman-group14-sha1, diffie-hellman-group-exchange-sha1)
  • SHA1-RSA signature verification (the ssh-rsa algorithm identifier)
  • DH group-exchange-sha256 minimum modulus raised 1024 → 2048

Users tunneling through SSH daemons older than OpenSSH 7.2 (2016) — or 8.2 (2020) for the modern RSA-SHA2 signatures — would break. Modern Linux distros and cloud bastion services are unaffected, but enterprise users with legacy Cisco/Juniper/older RHEL bastion hosts could see SSH tunnels stop working.

The DSA-key removal in paramiko 4 and the Python 3.8 drop are non-issues — pgAdmin requires Python 3.9+ and DSA was deprecated upstream a decade ago.

When to apply

When applied eventually, the release notes must state the SHA2 requirement explicitly and point legacy-server users at either upgrading the bastion or staying on a prior pgAdmin release.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant