-
Notifications
You must be signed in to change notification settings - Fork 170
Commit c5dcc24
authored
Bump cryptography from 41.0.5 to 41.0.7 (#557)
Bumps [cryptography](https://github.com/pyca/cryptography) from 41.0.5
to 41.0.7.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst">cryptography's
changelog</a>.</em></p>
<blockquote>
<p>41.0.7 - 2023-11-27</p>
<pre><code>
* Fixed compilation when using LibreSSL 3.8.2.
<p>.. _v41-0-6:</p>
<p>41.0.6 - 2023-11-27
</code></pre></p>
<ul>
<li>Fixed a null-pointer-dereference and segfault that could occur when
loading
certificates from a PKCS#7 bundle. Credit to <strong>pkuzco</strong> for
reporting the
issue. <strong>CVE-2023-49083</strong></li>
</ul>
<p>.. _v41-0-5:</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/pyca/cryptography/commit/4054596afc6f2b6cfcc54f56c35c34e0e429cb66"><code>4054596</code></a>
Backport LibreSSL 3.8.2 support for a 41.0.7 release (<a
href="https://redirect.github.com/pyca/cryptography/issues/9931">#9931</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/f09c261ca10a31fe41b1262306db7f8f1da0e48a"><code>f09c261</code></a>
41.0.6 release (<a
href="https://redirect.github.com/pyca/cryptography/issues/9927">#9927</a>)</li>
<li>See full diff in <a
href="https://github.com/pyca/cryptography/compare/41.0.5...41.0.7">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>1 file changed
+24
-24
lines changed+24-24
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments