oracle/oci-python-sdk

Cryptography security vulnerabilities CVE-2023-50782, CVE-2023-5678, CVE-2023-6129, CVE-2023-6237

nkatomeris-r7 opened this issue ยท 6 comments

Thanks @nkatomeris-r7. We will work on this to update the version set with no security vulnerability.

this is going to be a repeating issue, I'd suggest reconsidering how this dep is pinned #548

I've added a pr with the two line change, see #624

@jyotisaini any updates? requiring software with known cves is a bad look, especially given how trivial the fix is.

Hi @kapilt This is WIP at the moment and we are running tests internally to make sure nothing is breaking post upgrade. We will release the fix in the next release.