-
Notifications
You must be signed in to change notification settings - Fork 4.3k
Specify cryptography version. #34888
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
Checks are failing. Will not request review until checks are succeeding. If you'd like to override that behavior, comment |
Assigning reviewers: R: @liferoad for label python. Note: If you would like to opt out of this review, comment Available commands:
The PR bot will only process comments in the main thread (not review comments). |
cc @Abacn you probably still need to run the package updates as the post-release task. |
|
Reminder, please take a look at this pr: @liferoad |
@Abacn do we still need this PR? |
@@ -340,6 +340,7 @@ def get_portability_package_data(): | |||
ext_modules=extensions, | |||
install_requires=[ | |||
'crcmod>=1.7,<2.0', | |||
'cryptography>=44.0.1', |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
this will break beam installation on any python environment that has a dependency with upper bounded cryptography<44
To resolve vulnerability in container, update container requirements are sufficient
For vulneratibility in image
Thank you for your contribution! Follow this checklist to help us incorporate your contribution quickly and easily:
addresses #123
), if applicable. This will automatically add a link to the pull request in the issue. If you would like the issue to automatically close on merging the pull request, commentfixes #<ISSUE NUMBER>
instead.CHANGES.md
with noteworthy changes.See the Contributor Guide for more tips on how to make review process smoother.
To check the build health, please visit https://github.com/apache/beam/blob/master/.test-infra/BUILD_STATUS.md
GitHub Actions Tests Status (on master branch)
See CI.md for more information about GitHub Actions CI or the workflows README to see a list of phrases to trigger workflows.