navapbc / template-application-flask

Apache License 2.0
7 stars 3 forks source link

Update cryptography package #192

Closed lorenyu closed 1 year ago

lorenyu commented 1 year ago

Fixes CVE-2023-38325 / GHSA-cf7p-gm2m-833m: cryptography mishandles SSH certificates see https://github.com/navapbc/template-application-flask/security/dependabot/17

Fixes GHSA-jm77-qphf-c4w8: pyca/cryptography's wheels include vulnerable OpenSSL see https://github.com/navapbc/template-application-flask/security/dependabot/15