Skip to content

Update cryptography dependency upper bound#58

Merged
raghuramg753 merged 1 commit intomainfrom
soso1/cryptography
Mar 2, 2026
Merged

Update cryptography dependency upper bound#58
raghuramg753 merged 1 commit intomainfrom
soso1/cryptography

Conversation

@gps035
Copy link
Contributor

@gps035 gps035 commented Feb 18, 2026

This is causing a high security alert in our project. Because this is a hard dependency on a specific version, it will be the case for anyone using it, and not forcing a conflict resolution.

Also removes cffi from pyproject.toml as it is not directly used

Also remove direct dependency on cffi as it is only used by cryptography
@gps035 gps035 force-pushed the soso1/cryptography branch from 623f20d to 9d99a81 Compare February 20, 2026 14:24
@gps035 gps035 changed the title Remove unused cryptography dependency Update cryptography dependency upper bound Feb 20, 2026
@sonarqubecloud
Copy link

@gps035
Copy link
Contributor Author

gps035 commented Feb 20, 2026

Tested in NHSDigital/patient-flags-api/pull/1107 along with other open PRs

@raghuramg753 raghuramg753 merged commit ee37515 into main Mar 2, 2026
4 checks passed
@gps035
Copy link
Contributor Author

gps035 commented Mar 5, 2026

Closed #43

@gps035 gps035 deleted the soso1/cryptography branch March 5, 2026 10:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants