Commit 58bbd0b
committed
chore(deps): bump cryptography 49.0.0 -> 50.0.0 (GHSA-g6cj-pr64-35w5)
Resolves the OSV/Dependabot finding (alert #42, CVSS 8.2) that blocks the
Security Scan check on every PR: cryptography >=44.0.0,<50.0.0 is
vulnerable, first patched in 50.0.0.
cryptography is a transitive, optional dependency (pyspnego /
requests-kerberos, the kerberos extra) with no upper bound in pyproject,
so this is a lock-only bump — no pyproject change. Regenerated with
Poetry 2.2.1 via the internal PyPI proxy; the only diff is the
cryptography package block (version + wheel/sdist hashes), dependencies
and content-hash unchanged.
Co-authored-by: Isaac
Signed-off-by: eric-wang-1990 <e.wang@databricks.com>1 parent 97235e2 commit 58bbd0b
1 file changed
Lines changed: 47 additions & 47 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments