Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Bump cryptography from 3.2.1 to 3.3.2#155

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Open
dependabot wants to merge1 commit intodevelop
base:develop
Choose a base branch
Loading
fromdependabot/pip/cryptography-3.3.2

Conversation

@dependabot
Copy link

@dependabotdependabotbot commented on behalf ofgithubOct 3, 2022

Bumpscryptography from 3.2.1 to 3.3.2.

Changelog

Sourced fromcryptography's changelog.

3.3.2 - 2021-02-07

* **SECURITY ISSUE:** Fixed a bug where certain sequences of ``update()`` calls  when symmetrically encrypting very large payloads (>2GB) could result in an  integer overflow, leading to buffer overflows. *CVE-2020-36242* **Update:**  This fix is a workaround for *CVE-2021-23840* in OpenSSL, fixed in OpenSSL  1.1.1j.

.. _v3-3-1:

3.3.1 - 2020-12-09

  • Re-added a legacy symbol causing problems for olderpyOpenSSL users.

.. _v3-3:

3.3 - 2020-12-08

* **BACKWARDS INCOMPATIBLE:** Support for Python 3.5 has been removed due to  low usage and maintenance burden.* **BACKWARDS INCOMPATIBLE:** The  :class:`~cryptography.hazmat.primitives.ciphers.modes.GCM` and  :class:`~cryptography.hazmat.primitives.ciphers.aead.AESGCM` now require  64-bit to 1024-bit (8 byte to 128 byte) initialization vectors. This change  is to conform with an upcoming OpenSSL release that will no longer support  sizes outside this window.* **BACKWARDS INCOMPATIBLE:** When deserializing asymmetric keys we now  raise ``ValueError`` rather than ``UnsupportedAlgorithm`` when an  unsupported cipher is used. This change is to conform with an upcoming  OpenSSL release that will no longer distinguish between error types.* **BACKWARDS INCOMPATIBLE:** We no longer allow loading of finite field  Diffie-Hellman parameters of less than 512 bits in length. This change is to  conform with an upcoming OpenSSL release that no longer supports smaller  sizes. These keys were already wildly insecure and should not have been used  in any application outside of testing.* Updated Windows, macOS, and ``manylinux`` wheels to be compiled with  OpenSSL 1.1.1i.* Python 2 support is deprecated in ``cryptography``. This is the last release  that will support Python 2.* Added the  :meth:`~cryptography.hazmat.primitives.asymmetric.rsa.RSAPublicKey.recover_data_from_signature`  function to  :class:`~cryptography.hazmat.primitives.asymmetric.rsa.RSAPublicKey`  for recovering the signed data from an RSA signature.

.. _v3-2-1:

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting@dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from theSecurity Alerts page.

Bumps [cryptography](https://github.com/pyca/cryptography) from 3.2.1 to 3.3.2.- [Release notes](https://github.com/pyca/cryptography/releases)- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)- [Commits](pyca/cryptography@3.2.1...3.3.2)---updated-dependencies:- dependency-name: cryptography  dependency-type: indirect...Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotbot requested a review frommzbroch as acode ownerOctober 3, 2022 15:03
@dependabotdependabotbot added the dependenciesPull requests that update a dependency file labelOct 3, 2022
Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment

Reviewers

@mzbrochmzbrochAwaiting requested review from mzbrochmzbroch is a code owner

Assignees

No one assigned

Labels

dependenciesPull requests that update a dependency file

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

1 participant


[8]ページ先頭

©2009-2025 Movatter.jp