dbx
dbx copied to clipboard
Allow higher versions of cryptography to prevent CVE-2023-50782
Expected Behavior
cryptography>=42.0.0 should be possible
Current Behavior
cryptography is pinned to < 42.0.0
Hi Martin, working on that - thanks a lot for raising the issue!
Hi @renardeinside, what is the current status of the fix? The last release is now almost one year ago and the security issue is now open since 4 months. Thanks for an update! Best, Henry
almost ready in #863
Hi, is there anything we can do to help? It looks like the two checks are actually not executed ...
done, deployed with 0.8.19