ScilifelabDataCentre / dds_web

A cloud-based system for the delivery of data from SciLifeLab Facilities to their users (e.g. research group).
Other
7 stars 7 forks source link

Criptography update to address cve #1512

Closed rv0lt closed 6 months ago

rv0lt commented 6 months ago

Read this before submitting the PR

  1. Always create a Draft PR first
  2. Go through sections 1-5 below, fill them in and check all the boxes
  3. Make sure that the branch is updated; if there's an "Update branch" button at the bottom of the PR, rebase or update branch.
  4. When all boxes are checked, information is filled in, and the branch is updated: mark as Ready For Review and tag reviewers (top right)
  5. Once there is a submitted review, implement the suggestions (if reasonable, otherwise discuss) and request an new review.

If there is a field which you are unsure about, enter the edit mode of this description or go to the PR template; There are invisible comments providing descriptions which may be of help.

1. Description / Summary

Criptography update to address cve

https://cryptography.io/en/latest/changelog/

The update to version 42 have a backward incompatible change of dropping suport for LibreSSL < 3.7. However, we use openSSL in our code. SSL library is built in Python:

import ssl

ssl.OPENSSL_VERSION_INFO

2. Jira task / GitHub issue

https://scilifelab.atlassian.net/jira/software/projects/DDS/boards/13?selectedIssue=DDS-1892

3. Type of change

What type of change(s) does the PR contain?

Check the relevant boxes below. For an explanation of the different sections, enter edit mode of this PR description template.

4. Additional information

5. Actions / Scans

Check the boxes when the specified checks have passed.

For information on what the different checks do and how to fix it if they're failing, enter edit mode of this description or go to the PR template.

codecov[bot] commented 6 months ago

Codecov Report

All modified and coverable lines are covered by tests :white_check_mark:

Comparison is base (0e0a989) 91.48% compared to head (0f55988) 91.48%.

Additional details and impacted files ```diff @@ Coverage Diff @@ ## dev #1512 +/- ## ======================================= Coverage 91.48% 91.48% ======================================= Files 29 29 Lines 4637 4637 ======================================= Hits 4242 4242 Misses 395 395 ```

:umbrella: View full report in Codecov by Sentry.
:loudspeaker: Have feedback on the report? Share it here.