Skip to content

Cryptography and pillow vulnerabilities #1418

@adammcmaster

Description

@adammcmaster

There are security vulnerabilities in two of the TOM Toolkit's dependencies:

Currently the tomtoolkit package prevents the patched versions from being installed:

% poetry show tomtoolkit
 name         : tomtoolkit                   
 version      : 2.31.1                       
 description  : TOM Toolkit and base modules 

dependencies
...
 - cryptography <=46
 ...
 - pillow >9.2,<12.0
...

Please could these dependencies be bumped if possible?

Metadata

Metadata

Assignees

No one assigned

    Labels

    UserIssue Raised by a user

    Type

    No type

    Projects

    Status

    Closed

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions