[Snyk] Security upgrade cryptography from 3.4.7 to 46.0.6 - #6
[Snyk] Security upgrade cryptography from 3.4.7 to 46.0.6#6ryanmcmorrowsnyk wants to merge 1 commit into
Conversation
The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-15809188
|
This is a massive upgrade, jumping from version 3.4.7 to 46.0.6. This range covers dozens of major releases and introduces significant breaking changes, primarily related to the build environment and supported runtimes. Key Breaking Changes:
Recommendation: Due to the extensive changes across numerous versions, this upgrade must be handled with extreme care. Developers should verify their application in a test environment that matches the new requirements (Python 3.8+, modern OpenSSL/Rust for source builds). Code using advanced or now-deprecated APIs will require refactoring. Source: Cryptography Changelog
|
Snyk has created this PR to fix 1 vulnerabilities in the pip dependencies of this project.
Snyk changed the following file(s):
requirements.txtBreaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.