Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Cryptography dependency lock #2

Closed
vpolimenov opened this issue Mar 11, 2021 · 5 comments
Closed

Cryptography dependency lock #2

vpolimenov opened this issue Mar 11, 2021 · 5 comments

Comments

@vpolimenov
Copy link
Contributor

vpolimenov commented Mar 11, 2021

Hello,

I was wandering whether there is a particular reason why I can't use cryptography > 3.0.0 with this package?
https://github.com/odwyersoftware/azure-ad-verify-token/blob/master/requirements.txt#L2

I'm specifically asking because there is a known vulnerability with that library:
pyca/cryptography#5615
https://nvd.nist.gov/vuln/detail/CVE-2020-36242

Thanks in advance :)

@richardARPANET
Copy link
Contributor

No reason other than semver. Feel free to check if a wider version range functions and then I can widen the supported range in this package.

@vpolimenov
Copy link
Contributor Author

vpolimenov commented Mar 11, 2021

@richardARPANET thanks for the very quick answer!

If you could let me know when the new version is out it would be great :)

@richardARPANET
Copy link
Contributor

@vpolimenov Will release in a few hours. Just fixing a computer issue first

@richardARPANET
Copy link
Contributor

@vpolimenov 0.1.3 released

@vpolimenov
Copy link
Contributor Author

great! thank you very much 🙏

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants