oracle / oci-cli

Command Line Interface for Oracle Cloud Infrastructure
https://cloud.oracle.com/cloud-infrastructure
Other
449 stars 185 forks source link

oci-cli needs to stop depending on cryptography<43.0.0,>=3.2.1 because of a a security vulnerability #846

Closed nidal123 closed 1 month ago

nidal123 commented 2 months ago

When I try to fix it: oci-cli 3.48.0 has requirement cryptography<43.0.0,>=3.2.1, but you'll have cryptography 43.0.1 which is incompatible.

https://github.com/advisories/GHSA-h4gh-qq45-vh27

karthik-k-kamath commented 1 month ago

Thanks for highliting We (CLI team) are investigating this

Kanvipasricha commented 1 month ago

This issue is resolved in latest release. https://github.com/oracle/oci-cli/releases/tag/v3.49.0