-
Notifications
You must be signed in to change notification settings - Fork 5.5k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
stop depending on pycrypto #54115
Comments
pycrypto is unmaintained and has open security issues. Fixes: saltstack#54115
pycrypto is unmaintained and has open security issues. Fixes: saltstack#54115
pycrypto is unmaintained and has open security issues. Fixes: saltstack#54115
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions. If this issue is closed prematurely, please leave a comment and we will gladly reopen the issue. |
Thank you for updating this issue. It is no longer marked as stale. |
Note that OS packages (e.g. python3-crypto) should already have the security issues patched on currently-supported systems. |
Description of Issue
PyCrypto is unmaintained and has open security issues. This was already reported in e.g. #52674 but it is currently closed.
Steps to Reproduce Issue
Run
pip download salt
and check if it mentions pycrypto. It currently does, but it should not. It currently comes from https://github.com/saltstack/salt/blob/develop/requirements/zeromq.txt .Versions Report
Checked for 2019.2.0 via pip, and on branch develop by inspecting the above file.
The text was updated successfully, but these errors were encountered: