libcloud
libcloud copied to clipboard
Bump cryptography from 41.0.6 to 42.0.5
Bumps cryptography from 41.0.6 to 42.0.5.
Changelog
Sourced from cryptography's changelog.
42.0.5 - 2024-02-23
* Limit the number of name constraint checks that will be performed in :mod:`X.509 path validation <cryptography.x509.verification>` to protect against denial of service attacks. * Upgrade ``pyo3`` version, which fixes building on PowerPC... _v42-0-4:
42.0.4 - 2024-02-20
- Fixed a null-pointer-dereference and segfault that could occur when creating a PKCS#12 bundle. Credit to Alexander-Programming for reporting the issue. CVE-2024-26130
- Fixed ASN.1 encoding for PKCS7/SMIME signed messages. The fields
SMIMECapabilitiesandSignatureAlgorithmIdentifiershould now be correctly encoded according to the definitions in :rfc:2633:rfc:3370... _v42-0-3:
42.0.3 - 2024-02-15
* Fixed an initialization issue that caused key loading failures for some users... _v42-0-2:
42.0.2 - 2024-01-30
- Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.2.1.
- Fixed an issue that prevented the use of Python buffer protocol objects in
signandverifymethods on asymmetric keys.- Fixed an issue with incorrect keyword-argument naming with
EllipticCurvePrivateKey:meth:~cryptography.hazmat.primitives.asymmetric.ec.EllipticCurvePrivateKey.exchange,X25519PrivateKey:meth:~cryptography.hazmat.primitives.asymmetric.x25519.X25519PrivateKey.exchange,X448PrivateKey:meth:~cryptography.hazmat.primitives.asymmetric.x448.X448PrivateKey.exchange, andDHPrivateKey:meth:~cryptography.hazmat.primitives.asymmetric.dh.DHPrivateKey.exchange... _v42-0-1:
42.0.1 - 2024-01-24
</tr></table>
... (truncated)
Commits
33833f0Release 42.0.5 (#10470)4be53bfAdded a budget for NC checks to protect against DoS (#10467) (#10468)8e9de30Bump pyo3 from 0.20.2 to 0.20.3 in /src/rust (#10462) (#10465)fe18470Bump for 42.0.4 release (#10445)aaa2dd0Fix ASN.1 issues in PKCS#7 and S/MIME signing (#10373) (#10442)7a4d012Fixes #10422 -- don't crash when a PKCS#12 key and cert don't match (#10423) ...df314bbbackport actions m1 switch to 42.0.x (#10415)c49a7a5changelog and version bump for 42.0.3 (#10396)396bcf6fix provider loading take two (#10390) (#10395)0e0e46fbackport: initialize openssl's legacy provider in rust (#10323) (#10333)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)