-
Notifications
You must be signed in to change notification settings - Fork 6
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Cryptography dependency lock #2
Comments
No reason other than semver. Feel free to check if a wider version range functions and then I can widen the supported range in this package. |
@richardARPANET thanks for the very quick answer! If you could let me know when the new version is out it would be great :) |
@vpolimenov Will release in a few hours. Just fixing a computer issue first |
@vpolimenov 0.1.3 released |
great! thank you very much 🙏 |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Hello,
I was wandering whether there is a particular reason why I can't use cryptography > 3.0.0 with this package?
https://github.com/odwyersoftware/azure-ad-verify-token/blob/master/requirements.txt#L2
I'm specifically asking because there is a known vulnerability with that library:
pyca/cryptography#5615
https://nvd.nist.gov/vuln/detail/CVE-2020-36242
Thanks in advance :)
The text was updated successfully, but these errors were encountered: