Update cryptography requirement from ~=37.0.0 to ~=37.0.1
Created by: dependabot[bot]
Updates the requirements on cryptography to permit the latest version.
Changelog
Sourced from cryptography's changelog.
37.0.1 - 2022-04-27
* Fixed an issue where parsing an encrypted private key with the public loader functions would hang waiting for console input on OpenSSL 3.0.x rather than raising an error. * Restored some legacy symbols for older ``pyOpenSSL`` users. These will be removed again in the future, so ``pyOpenSSL`` users should still upgrade to the latest version of that package when they upgrade ``cryptography``. .. _v37-0-0: 37.0.0 - 2022-04-26
- Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.0.2.
- BACKWARDS INCOMPATIBLE: Dropped support for LibreSSL 2.9.x and 3.0.x. The new minimum LibreSSL version is 3.1+.
- BACKWARDS INCOMPATIBLE: Removed
signer
andverifier
methods from the public key and private key classes. These methods were originally deprecated in version 2.0, but had an extended deprecation timeline due to usage. Any remaining users should transition tosign
andverify
.- Deprecated OpenSSL 1.1.0 support. OpenSSL 1.1.0 is no longer supported by the OpenSSL project. The next release of
cryptography
will be the last to support compiling with OpenSSL 1.1.0.- Deprecated Python 3.6 support. Python 3.6 is no longer supported by the Python core team. Support for Python 3.6 will be removed in a future
cryptography
release.- Deprecated the current minimum supported Rust version (MSRV) of 1.41.0. In the next release we will raise MSRV to 1.48.0. Users with the latest
pip
will typically get a wheel and not need Rust installed, but check :doc:/installation
for documentation on installing a newerrustc
if required.- Deprecated :class:
~cryptography.hazmat.primitives.ciphers.algorithms.CAST5
, :class:~cryptography.hazmat.primitives.ciphers.algorithms.SEED
, :class:~cryptography.hazmat.primitives.ciphers.algorithms.IDEA
, and :class:~cryptography.hazmat.primitives.ciphers.algorithms.Blowfish
because they are legacy algorithms with extremely low usage. These will be removed in a future version ofcryptography
.- Added limited support for distinguished names containing a bit string.
- We now ship
universal2
wheels on macOS, which contain botharm64
andx86_64
architectures. Users on macOS should upgrade to the latestpip
to ensure they can use this wheel, although we will continue to shipx86_64
specific wheels for now to ease the transition.- This will be the final release for which we ship
manylinux2010
wheels. Going forward the minimum supportedmanylinux
ABI for our wheels will bemanylinux2014
. The vast majority of users will continue to receivemanylinux
wheels provided they have an up to datepip
. For PyPy wheels this release already requiresmanylinux2014
for compatibility
... (truncated)
Commits
-
3fb93cf
37.0.1 changelog and version bump (#7139) -
8ec3192
restore some bindings for older pyopenssl temporarily (#7137) -
2d4e0b2
Fix parsing of priv keys via pub key APIs to error properly in ossl3 (#7135) -
82d9339
Add typings to default_backend() (#7133) -
cfdfb1a
update wheel builder for lib64 path (#7122) -
c450331
pep 527 actually prohibits xztar (#7121) - See full diff in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)