fix(deps): make cryptography an optional test dependency - #323
Open
AlexanderKomarov wants to merge 1 commit into
Open
fix(deps): make cryptography an optional test dependency#323AlexanderKomarov wants to merge 1 commit into
AlexanderKomarov wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes in this pull request
cryptographyis declared as a runtime dependency, but it is not used by theruntime bindings in
src/c2pa— all cryptographic operations (hashing, COSEsigning/verification, certificate-chain validation) happen inside the bundled
native c2pa-rs library. It is only imported by the test suite and the examples
to implement
Signer.from_callbackhelpers (ES256 / ECDSA over PEM keys);requirements.txteven noted it was "only used in the training example".Declaring it under
[project.dependencies]forces every downstream consumer toinstall
cryptography(~14 MB, bundles its own OpenSSL) with no runtime benefit,enlarging install size and CVE/compliance surface.
This PR:
cryptographyto atestoptional-dependency inpyproject.toml(mirroring
requirements-dev.txt);requirements.txt(which already flagged it as example-only);[test]extra in the wheel-test CI jobs sothe suite still has it.
No runtime behaviour changes.
Verified locally: a wheel built from this branch installs
c2pa-python,toml,requestsonly (nocryptography), imports fine, and reads a realsigned C2PA asset;
pip install "<wheel>[test]"pullscryptographyfor thetests.
Checklist
TO DOitems (or similar) have been entered as GitHub issues — N/A (no TODOs)