hey Arun, This package was updated recently (https://github.com/apache/beam/pull/39756) and will be shipped with the next release.
1. If you use Dataflow, Google Cloud recommends using custom container images to manage security issues responsively. If you have strict Service Level Agreement (SLA) requirements for security, such as those for FedRAMP compliance, using custom containers lets you manage your own Apache Beam versions and patch cycles, rather than relying on the Apache Beam open source release schedule - see more https://docs.cloud.google.com/dataflow/docs/guides/using-custom-containers , https://docs.cloud.google.com/dataflow/docs/resources/shared-responsibility#customers_responsibilities - let me know if this helps you address your problem. 2. Team is actively uses vulnerability scanner reports ( https://docs.cloud.google.com/artifact-registry/docs/analysis) but feel free to raise issues/cases or contribute if something is still missing. Radek On Mon, Sep 14, 2026 at 5:50 PM Arun Periasamy <[email protected]> wrote: > > Hi Apache Beam Team, > > We recently evaluated Apache Beam 2.76.0 for Python and noticed that the > release currently restricts the `cryptography` dependency to versions > earlier than 49.0.0. > > Our organization uses Snyk for vulnerability management, and Snyk reports > known security vulnerabilities in versions of `cryptography` below 49.0.0. > As a result, we are unable to adopt Apache Beam 2.76.0 in our environment. > This issue may also affect other organizations with similar security > compliance requirements. > > Could you please help clarify the following: > > > 1. Is it possible to address this issue through a security-focused > patch release that supports a non-vulnerable version of the `cryptography` > package? > 2. For future releases, could the project consider incorporating > dependency vulnerability reviews and remediation as part of the release > process to help minimize exposure to known CVEs? > 3. > 4. For reference, the Snyk vulnerability report is available here: > 5. > 6. https://security.snyk.io/package/pip/cryptography/versions > 7. > 8. > 9. Thank you for your time and assistance. > > > Thanks > Arun >
