ingest-file
ingest-file copied to clipboard
Bump cryptography from 41.0.7 to 42.0.8
Bumps cryptography from 41.0.7 to 42.0.8.
Changelog
Sourced from cryptography's changelog.
42.0.8 - 2024-06-04
* Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.2.2... _v42-0-7:
42.0.7 - 2024-05-06
- Restored Windows 7 compatibility for our pre-built wheels. Note that we do not test on Windows 7 and wheels for our next release will not support it. Microsoft no longer provides support for Windows 7 and users are encouraged to upgrade.
.. _v42-0-6:
42.0.6 - 2024-05-04
* Fixed compilation when using LibreSSL 3.9.1... _v42-0-5:
42.0.5 - 2024-02-23
- Limit the number of name constraint checks that will be performed in :mod:
X.509 path validation <cryptography.x509.verification>to protect against denial of service attacks.- Upgrade
pyo3version, which fixes building on PowerPC... _v42-0-4:
42.0.4 - 2024-02-20
* Fixed a null-pointer-dereference and segfault that could occur when creating a PKCS#12 bundle. Credit to **Alexander-Programming** for reporting the issue. **CVE-2024-26130** * Fixed ASN.1 encoding for PKCS7/SMIME signed messages. The fields ``SMIMECapabilities`` and ``SignatureAlgorithmIdentifier`` should now be correctly encoded according to the definitions in :rfc:`2633` :rfc:`3370`... _v42-0-3:
42.0.3 - 2024-02-15
- Fixed an initialization issue that caused key loading failures for some
... (truncated)
Commits
761ef4bbump for 42.0.8 release (#11072)0cc7fc3Prepare for 42.0.7 release (#10949)cfad004Prepare backports for 42.0.6 release (#10929)33833f0Release 42.0.5 (#10470)4be53bfAdded a budget for NC checks to protect against DoS (#10467) (#10468)8e9de30Bump pyo3 from 0.20.2 to 0.20.3 in /src/rust (#10462) (#10465)fe18470Bump for 42.0.4 release (#10445)aaa2dd0Fix ASN.1 issues in PKCS#7 and S/MIME signing (#10373) (#10442)7a4d012Fixes #10422 -- don't crash when a PKCS#12 key and cert don't match (#10423) ...df314bbbackport actions m1 switch to 42.0.x (#10415)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)