fair-research / bdbag

Big Data Bag Utilities
https://fair-research.org
Apache License 2.0
50 stars 22 forks source link

Bump rsa from 4.5 to 4.7 #43

Closed dependabot[bot] closed 3 years ago

dependabot[bot] commented 3 years ago

Bumps rsa from 4.5 to 4.7.

Changelog

Sourced from rsa's changelog.

Version 4.7 - released 2021-01-10

  • Fix #165: CVE-2020-25658 - Bleichenbacher-style timing oracle in PKCS#1 v1.5 decryption code
  • Add padding length check as described by PKCS#1 v1.5 (Fixes #164)
  • Reuse of blinding factors to speed up blinding operations. Fixes #162.
  • Declare & test support for Python 3.9

Version 4.4 & 4.6 - released 2020-06-12

Version 4.4 and 4.6 are almost a re-tagged release of version 4.2. It requires Python 3.5+. To avoid older Python installations from trying to upgrade to RSA 4.4, this is now made explicit in the python_requires argument in setup.py. There was a mistake releasing 4.4 as "3.5+ only", which made it necessary to retag 4.4 as 4.6 as well.

No functional changes compared to version 4.2.

Commits
  • fa3282a Bumped version to 4.7
  • a364e82 Marked version 4.7 as released
  • 539c54a Fix #170: mistake in examples of documentation
  • b81e317 Declare support for and test Python 3.9
  • 06ec1ea Fix #162: Blinding uses slow algorithm
  • 341e5c4 Directly raise DecryptionError when crypto length is bad
  • f254895 Use bytes.find() instead of bytes.index()
  • 240b0d8 Add link to changelog
  • f878c37 Fix #164: Add padding length check as described by PKCS#1 v1.5
  • dae8ce0 Fix #165: CVE-2020-25658 - Bleichenbacher-style timing oracle
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/fair-research/bdbag/network/alerts).
dependabot[bot] commented 3 years ago

Looks like rsa is up-to-date now, so this is no longer needed.