Skip to content
This repository has been archived by the owner on Jan 27, 2023. It is now read-only.

Fixes #909 by updating cryptography lib to 3.3.2 #922

Merged
merged 1 commit into from
Feb 26, 2021

Conversation

zhill
Copy link
Member

@zhill zhill commented Feb 26, 2021

Only a single minor version update, previously engine was installing 3.3.1 as indirect dependency, but this update is only for a single fix in the library: https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst#332---2021-02-07

@zhill zhill linked an issue Feb 26, 2021 that may be closed by this pull request
Signed-off-by: Zach Hill <zach@anchore.com>
Copy link
Contributor

@dakaneye dakaneye left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM ! Integer Overflows == bad

@zhill zhill merged commit ad10941 into anchore:v0.9.2-dev Feb 26, 2021
@zhill zhill deleted the issue-909 branch May 14, 2021 02:50
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

address VULNDB-248976/CVE-2020-36242 for next release
2 participants