From a71cd37a86214d7e22441bf1235829ed063f8ed8 Mon Sep 17 00:00:00 2001 From: Hugo van Kemenade Date: Tue, 25 Oct 2022 06:08:36 +0300 Subject: [PATCH] Require pyjwt>=2.4.0 to avoid CVE-2022-29217 (#2333) --- requirements.txt | 2 +- setup.py | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/requirements.txt b/requirements.txt index ae9478587a..bc82296fc8 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,6 +1,6 @@ pynacl>=1.4.0 requests>=2.14.0 -pyjwt>=2.0 +pyjwt>=2.4.0 sphinx<3 Jinja2<3.1 sphinx-rtd-theme<1.1 diff --git a/setup.py b/setup.py index acd8c328c0..bd22abb837 100755 --- a/setup.py +++ b/setup.py @@ -106,7 +106,7 @@ python_requires=">=3.7", install_requires=[ "deprecated", - "pyjwt>=2.0", + "pyjwt>=2.4.0", "pynacl>=1.4.0", "requests>=2.14.0", ],