Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow pycryptodome ~> 3.6.6 #5

Open
pedropregueiro opened this issue Aug 29, 2018 · 5 comments
Open

Allow pycryptodome ~> 3.6.6 #5

pedropregueiro opened this issue Aug 29, 2018 · 5 comments

Comments

@pedropregueiro
Copy link

pedropregueiro commented Aug 29, 2018

Github is warning users about a security issue with pycroptodome < 3.6.6.:

screenshot 2018-08-29 17 05 29

Apparently, there's some sort of vulnerability with older versions:
https://nvd.nist.gov/vuln/detail/CVE-2018-15560

Is this something that should be changed on this package to allow installations with pycroptodome ~> 3.6.6.?

Btw, related to #2

@dwright213
Copy link

Im only doing basic stuff with it (warrant-lite in a flask/uwsgi app) but it seems to run with pycryptodome 3.6.6. I still haven't run any tests tho.

@mryalamanchi
Copy link

mryalamanchi commented Jul 12, 2019

@dwright213 @pedropregueiro I just tried installing this module with pycryptodome==3.8.2 and it gave me an incompatibility warning.

python-jose-cryptodome 1.3.2 has requirement pycryptodome<3.4.0,>=3.3.1, but you'll have pycryptodome 3.8.2 which is incompatible.

Did you happen to come across any such warning/error?

@BKPepe
Copy link

BKPepe commented Jul 13, 2019

ping @bjinwright would be good if you can solve this and release a new version, which will be also included in warrant. See capless/warrant#144

@mgrazebrook
Copy link

Using the out of date version also prevents it installing on Windows - though there is a workaround:
#4 (comment)

@Integralist
Copy link

Sigh. I see this is still an open issue 😞

ERROR: python-jose-cryptodome 1.3.2 has requirement pycryptodome<3.4.0,>=3.3.1, but you'll have pycryptodome 3.6.6 which is incompatible.

Thankfully it sounds like it has built and that no one has seen issues yet.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

6 participants