Skip to content

Avoid insecure pycryptodome#16238

Merged
balloob merged 1 commit intodevfrom
constraints-pycryptodome
Aug 28, 2018
Merged

Avoid insecure pycryptodome#16238
balloob merged 1 commit intodevfrom
constraints-pycryptodome

Conversation

@balloob
Copy link
Copy Markdown
Member

@balloob balloob commented Aug 28, 2018

Description:

PyCryptodome < 3.6.6 has a vulnerability. Although not used directly by Home Assistant, it is used by some of our dependencies. This will make sure that we don't install vulnerable versions.

@balloob balloob added this to the 0.77 milestone Aug 28, 2018
@homeassistant homeassistant added core small-pr PRs with less than 30 lines. cla-signed labels Aug 28, 2018
@balloob balloob force-pushed the constraints-pycryptodome branch from f14808f to c299efd Compare August 28, 2018 09:26
@ghost ghost assigned balloob Aug 28, 2018
@ghost ghost added the in progress label Aug 28, 2018
@balloob balloob merged commit 12709ce into dev Aug 28, 2018
@balloob balloob deleted the constraints-pycryptodome branch August 28, 2018 10:49
@ghost ghost removed the in progress label Aug 28, 2018
balloob added a commit that referenced this pull request Aug 28, 2018
@balloob balloob mentioned this pull request Aug 29, 2018
girlpunk pushed a commit to girlpunk/home-assistant that referenced this pull request Sep 4, 2018
@home-assistant home-assistant locked and limited conversation to collaborators Dec 10, 2018
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants