Skip to content

Commit 58bbd0b

Browse files
chore(deps): bump cryptography 49.0.0 -> 50.0.0 (GHSA-g6cj-pr64-35w5)
Resolves the OSV/Dependabot finding (alert #42, CVSS 8.2) that blocks the Security Scan check on every PR: cryptography >=44.0.0,<50.0.0 is vulnerable, first patched in 50.0.0. cryptography is a transitive, optional dependency (pyspnego / requests-kerberos, the kerberos extra) with no upper bound in pyproject, so this is a lock-only bump — no pyproject change. Regenerated with Poetry 2.2.1 via the internal PyPI proxy; the only diff is the cryptography package block (version + wheel/sdist hashes), dependencies and content-hash unchanged. Co-authored-by: Isaac Signed-off-by: eric-wang-1990 <e.wang@databricks.com>
1 parent 97235e2 commit 58bbd0b

1 file changed

Lines changed: 47 additions & 47 deletions

File tree

poetry.lock

Lines changed: 47 additions & 47 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)