We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
There is a high-severity vulnerability in Cryptography < 42, see GHSA-3ww4-gg4f-jr7f
Since this library forces Crytpography < 42, I cannot upgrade to a non-vulnerable version.
The dependency version for Cryptography is relaxed at
auth0-python/pyproject.toml
Line 31 in a31c62b
No workaround is available for Poetry since this is a hard requirement from the auth0-python library.
No response
The text was updated successfully, but these errors were encountered:
Would really appreciate this being addressed.
Sorry, something went wrong.
please address. this is a high vulnerability being detected as it is now on https://nvd.nist.gov/vuln/detail/CVE-2024-26130
#597 a pr is already out there ready for approval.
Update cryptography dependency (#605)
d0bcc22
fixes #600
Successfully merging a pull request may close this issue.
Checklist
Describe the problem you'd like to have solved
There is a high-severity vulnerability in Cryptography < 42, see GHSA-3ww4-gg4f-jr7f
Since this library forces Crytpography < 42, I cannot upgrade to a non-vulnerable version.
Describe the ideal solution
The dependency version for Cryptography is relaxed at
auth0-python/pyproject.toml
Line 31 in a31c62b
Alternatives and current workarounds
No workaround is available for Poetry since this is a hard requirement from the auth0-python library.
Additional context
No response
The text was updated successfully, but these errors were encountered: