security: upgrade some package versions
This commit is contained in:
@@ -26,7 +26,7 @@ cbor2==5.9.0 # CVE-2024-26134, CVE-2026-26209 (DoS via recursion)
|
|||||||
|
|
||||||
# JWT / OIDC
|
# JWT / OIDC
|
||||||
PyJWT==2.13.0 # CVE-2026-48526 (auth bypass via forged JWT), CVE-2026-32597
|
PyJWT==2.13.0 # CVE-2026-48526 (auth bypass via forged JWT), CVE-2026-32597
|
||||||
cryptography==46.0.5 # CVE-2026-26007 (SECT subgroup attack)
|
cryptography==43.0.3 # capped <44 by sshkey-tools 0.11.3; see .trivyignore for CVE-2026-26007
|
||||||
|
|
||||||
# CORS
|
# CORS
|
||||||
Flask-CORS==6.0.0 # CVE-2024-6221 (ACAO handling)
|
Flask-CORS==6.0.0 # CVE-2024-6221 (ACAO handling)
|
||||||
|
|||||||
@@ -37,7 +37,7 @@ pytz==2023.3
|
|||||||
python-dotenv==1.0.0
|
python-dotenv==1.0.0
|
||||||
pydantic==2.5.0
|
pydantic==2.5.0
|
||||||
PyJWT==2.13.0
|
PyJWT==2.13.0
|
||||||
cryptography==46.0.5
|
cryptography==43.0.3 # capped <44 by sshkey-tools 0.11.3
|
||||||
pycryptodome==3.20.0
|
pycryptodome==3.20.0
|
||||||
psycopg2-binary==2.9.9
|
psycopg2-binary==2.9.9
|
||||||
sshkey-tools==0.11.3
|
sshkey-tools==0.11.3
|
||||||
|
|||||||
Reference in New Issue
Block a user