-
Notifications
You must be signed in to change notification settings - Fork 1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bump the cryptography version to 42 #3950
Comments
snowflake-connector-python is blocking the bump https://github.com/snowflakedb/snowflake-connector-python/blob/v3.7.0/setup.cfg#L48 |
back to this one, since snowflake connector is no longer blocking should we set 42 is lower bound for |
No, I don't think so, let's leave it up for the users. Might get in the way with installing some other packages that people use with feast. snowflake also bumped only the upper bound. |
Thanks, guys. 👍 |
Is your feature request related to a problem? Please describe.
cryptography<42
package has some medium vulnerabilities. Example: https://scout.docker.com/vulnerabilities/id/CVE-2023-50782?s=github&n=cryptography&t=pypi&vr=%3C42.0.0&utm_source=desktop&utm_medium=ExternalLinkstarlette and fastapi had some high vulnerabilities but that was recently bumped up and thanks to that, they are removed.
Describe the solution you'd like
Bump the cryptography package to>=42. Nice to have: bumping up of other compatible packages also.
The text was updated successfully, but these errors were encountered: