Conversation
This PR upgrade pyopenssl dependency. Current constraints is `<24.3.0`(up to 24.2.x). New constratints is `<24.4.0`(up to 24.3.x). This PR is for addressing security alert `GHSA-79v4-65xg-pq4g`. GHSA-79v4-65xg-pq4g // I guess this constratints is for pyopenssl->cryptography migration. IdentityPython#977 IdentityPython@735bfa5
|
First off, thank you for the great work in building and maintaining this project! |
Co-authored-by: Mariusz Felisiak <felisiak.mariusz@gmail.com>
|
Note that #977 aims to remove pyopenssl all together and conflicts with this PR |
|
Hi, In Openstack we also have to bump pyopenssl (https://review.opendev.org/c/openstack/requirements/+/958191/2/upper-constraints.txt ), thanks for working on this (or removing the dependency to pyopenssl) |
|
With 735bfa5 pyOpenSSL was restricted to This disallows us to update pyOpenSSL atm. Given this issue, I cannot proceed to merge this. |
Description
This PR upgrade pyopenssl dependency to address security alert.
The feature or problem addressed by this PR
This PR is for addressing security alert
GHSA-79v4-65xg-pq4g.GHSA-79v4-65xg-pq4g
What your changes do and why you chose this solution
Current constraints is
<24.3.0(up to 24.2.x). New constratints is<24.4.0(up to 24.3.x).Checklist
// I guess this constratints is for pyopenssl->cryptography migration.
#977 735bfa5