tree 3301208ed40e712f32ed7d7fdaeee8ba3d510a77
parent 46f4c25e716a7002453e4b24d5257a0913d77482
author dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 1707201347 +0900
committer GitHub <noreply@github.com> 1707201347 +0000
gpgsig -----BEGIN PGP SIGNATURE-----
 
 wsFcBAABCAAQBQJlwdNTCRC1aQ7uu5UhlAAA/SIQAGOs5vtlIQyjSuKxsmJTWwU0
 K3/lQChx4kBdCegM+HO650dIujb9JpoU495e+dAwiScF/wcUk6EWgxxBarrsoMcR
 ISAl3klhLkekBbJBax2e+rTfwGrw4a/+b6bJmKAJrU5SdowiQDVfMiPibHid1oIA
 AR4OXN1O7M+rXO6qFe2aWrB6YyQ8X9/RetJ6eN9PXMUUtz7JF4n0gTObOZTikqxz
 T/2QdowVVuNMQAwzP3cBa/81lPg4o0cUsxR80FK8VrXG/fWzJvfrWt690tI3RVt6
 ddrDOaWPPYl3Dv0U8sTHPLJcQSpu/ggLt4JRZgkkeBSLEjGB6y5FmUrov+UkMXl1
 XkVhJVHEc2aCBQHjuQODuq1J4pGQQZiQ+bcT8YleuUrIRUGqOHVPwOMtBEWMPxYD
 qe3VtuWUX44hYw3AE5BDm9NCsf+8qJcYkxY70y80ZbpCkB3VkUfyhWgcWU+ub/zW
 fwD7XJTRwJICBrOZG5IfOL8qQo5NcJc77OSNUlmWaFsDNXitqmBMQCbwLflc7RJR
 9sK4KyIp2Dag6OvPJ5Jw/fpy+EdsyE1oFjar1bWXsYAL78gfKP3cP/gqZoGx8eid
 /fJZEAhTbLREzk+tWq2GYlUZ4HqHxJt7EElP5pXuov1oKPupAJZGYmonCK++Fvmr
 WjzmS5UYmVYpWc//ROBW
 =Ok0P
 -----END PGP SIGNATURE-----
 

build(deps): bump cryptography from 39.0.0 to 41.0.6 in /tools/publish (#1581)

Bumps [cryptography](https://github.com/pyca/cryptography) from 39.0.0
to 41.0.6.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst">cryptography's
changelog</a>.</em></p>
<blockquote>
<p>41.0.6 - 2023-11-27</p>
<pre><code>
* Fixed a null-pointer-dereference and segfault that could occur when
loading
certificates from a PKCS#7 bundle. Credit to **pkuzco** for reporting
the
  issue. **CVE-2023-49083**
<p>.. _v41-0-5:</p>
<p>41.0.5 - 2023-10-24
</code></pre></p>
<ul>
<li>Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL
3.1.4.</li>
<li>Added a function to support an upcoming <code>pyOpenSSL</code>
release.</li>
</ul>
<p>.. _v41-0-4:</p>
<p>41.0.4 - 2023-09-19</p>
<pre><code>
* Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL
3.1.3.
<p>.. _v41-0-3:</p>
<p>41.0.3 - 2023-08-01
</code></pre></p>
<ul>
<li>Fixed performance regression loading DH public keys.</li>
<li>Fixed a memory leak when using

:class:<code>~cryptography.hazmat.primitives.ciphers.aead.ChaCha20Poly1305</code>.</li>
<li>Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL
3.1.2.</li>
</ul>
<p>.. _v41-0-2:</p>
<p>41.0.2 - 2023-07-10</p>
<pre><code>
* Fixed bugs in creating and parsing SSH certificates where critical
options
with values were handled incorrectly. Certificates are now created
correctly
  and parsing accepts correct values as well as the previously generated
invalid forms with a warning. In the next release, support for parsing
these
  invalid forms will be removed.
<p>.. _v41-0-1:</p>
<p>41.0.1 - 2023-06-01
</code></pre></p>
<ul>
<li>Temporarily allow invalid ECDSA signature algorithm parameters in
X.509
certificates, which are generated by older versions of Java.</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/pyca/cryptography/commit/f09c261ca10a31fe41b1262306db7f8f1da0e48a"><code>f09c261</code></a>
41.0.6 release (<a
href="https://redirect.github.com/pyca/cryptography/issues/9927">#9927</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/5012bedaef2dc60af3955306774b77ef379116e3"><code>5012bed</code></a>
bump for 41.0.5 release (<a
href="https://redirect.github.com/pyca/cryptography/issues/9766">#9766</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/563b1193997512836603777d31e2ea281b3dc79a"><code>563b119</code></a>
Added binding needed for pyOpenSSL (<a
href="https://redirect.github.com/pyca/cryptography/issues/9739">#9739</a>)
(<a
href="https://redirect.github.com/pyca/cryptography/issues/9740">#9740</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/fc11bce6930e591ce26a2317b31b9ce2b3e25512"><code>fc11bce</code></a>
bump for 41.0.4 (<a
href="https://redirect.github.com/pyca/cryptography/issues/9629">#9629</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/b22271cf3c3dd8dc8978f8f4b00b5c7060b6538d"><code>b22271c</code></a>
bump for 41.0.3 (<a
href="https://redirect.github.com/pyca/cryptography/issues/9330">#9330</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/774a4a16cbd22a89fdb4195ade9e4fcee27a7afa"><code>774a4a1</code></a>
Only check DH key validity when loading a private key. (<a
href="https://redirect.github.com/pyca/cryptography/issues/9071">#9071</a>)
(<a
href="https://redirect.github.com/pyca/cryptography/issues/9319">#9319</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/bfa4d95f0f356f2d535efd5c775e0fb3efe90ef2"><code>bfa4d95</code></a>
changelog for 41.0.3 (<a
href="https://redirect.github.com/pyca/cryptography/issues/9320">#9320</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/0da7165aa73c0a4865b0a4d9e019db3c16eea55a"><code>0da7165</code></a>
backport fix the memory leak in fixedpool (<a
href="https://redirect.github.com/pyca/cryptography/issues/9272">#9272</a>)
(<a
href="https://redirect.github.com/pyca/cryptography/issues/9309">#9309</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/7431db737cf0407560fac689d24f1d2e5efc349d"><code>7431db7</code></a>
bump for 41.0.2 (<a
href="https://redirect.github.com/pyca/cryptography/issues/9215">#9215</a>)</li>
<li><a
href="https://github.com/pyca/cryptography/commit/e190ef190525999d1f599cf8c3aef5cb7f3a8bc4"><code>e190ef1</code></a>
Backport ssh cert fix (<a
href="https://redirect.github.com/pyca/cryptography/issues/9211">#9211</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/pyca/cryptography/compare/39.0.0...41.0.6">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=cryptography&package-manager=pip&previous-version=39.0.0&new-version=41.0.6)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/bazelbuild/rules_python/network/alerts).

</details>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Richard Levasseur <rlevasseur@google.com>