Commit 3cf2010
deps(security): cryptography >= 46.0.7 (GHSA-p423-j2cm-9vmq) (#227)
Closes the single open Dependabot advisory on GeoSync main:
GHSA-p423-j2cm-9vmq — Cryptography buffer-overflow with
non-contiguous buffers (moderate). Vulnerable range
``>= 45.0.0, < 46.0.7``; current pin 46.0.6; fix 46.0.7+.
Bumps the floor in the three source-of-truth manifests
(``pyproject.toml``, ``requirements.txt``, ``requirements-scan.txt``)
and the generated ``sbom/combined-requirements.txt`` together so the
SBOM stays consistent with the lockfiles.
Minor point-release of a widely-deployed library — no API change
on the code paths we use (cipher/hash/x509 primitives).
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>1 parent e1949e5 commit 3cf2010
4 files changed
Lines changed: 4 additions & 4 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
67 | 67 | | |
68 | 68 | | |
69 | 69 | | |
70 | | - | |
| 70 | + | |
71 | 71 | | |
72 | 72 | | |
73 | 73 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
54 | 54 | | |
55 | 55 | | |
56 | 56 | | |
57 | | - | |
| 57 | + | |
58 | 58 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
51 | 51 | | |
52 | 52 | | |
53 | 53 | | |
54 | | - | |
| 54 | + | |
55 | 55 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
28 | 28 | | |
29 | 29 | | |
30 | 30 | | |
31 | | - | |
| 31 | + | |
32 | 32 | | |
33 | 33 | | |
34 | 34 | | |
| |||
0 commit comments