pkgsrc-Changes-HG archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

[pkgsrc/trunk]: pkgsrc/security py-cryptography[_vectors]: updated to 2.3



details:   https://anonhg.NetBSD.org/pkgsrc/rev/214e1f1d49c6
branches:  trunk
changeset: 382971:214e1f1d49c6
user:      adam <adam%pkgsrc.org@localhost>
date:      Thu Jul 19 09:24:37 2018 +0000

description:
py-cryptography[_vectors]: updated to 2.3

2.3:

SECURITY ISSUE: :meth:~cryptography.hazmat.primitives.ciphers.AEADDecryptionContext.finalize_with_tag allowed tag truncation by default which can allow tag forgery in some cases. The method now 
enforces the min_tag_length provided to the :class:~cryptography.hazmat.primitives.ciphers.modes.GCM constructor. CVE-2018-10903
Added support for Python 3.7.
Added :meth:~cryptography.fernet.Fernet.extract_timestamp to get the authenticated timestamp of a :doc:Fernet </fernet> token.
Support for Python 2.7.x without hmac.compare_digest has been deprecated. We will require Python 2.7.7 or higher (or 2.7.6 on Ubuntu) in the next cryptography release.
Fixed multiple issues preventing cryptography from compiling against LibreSSL 2.7.x.
Added :class:~cryptography.x509.CertificateRevocationList.get_revoked_certificate_by_serial_number for quick serial number searches in CRLs.
The :class:~cryptography.x509.RelativeDistinguishedName class now preserves the order of attributes. Duplicate attributes now raise an error instead of silently discarding duplicates.
:func:~cryptography.hazmat.primitives.keywrap.aes_key_unwrap and :func:~cryptography.hazmat.primitives.keywrap.aes_key_unwrap_with_padding now raise 
:class:~cryptography.hazmat.primitives.keywrap.InvalidUnwrap if the wrapped key is an invalid length, instead of ValueError.

diffstat:

 security/py-cryptography/Makefile         |   4 ++--
 security/py-cryptography/distinfo         |  10 +++++-----
 security/py-cryptography_vectors/Makefile |   4 ++--
 security/py-cryptography_vectors/PLIST    |  31 ++++++++++++++++++++++++++++++-
 security/py-cryptography_vectors/distinfo |  10 +++++-----
 5 files changed, 44 insertions(+), 15 deletions(-)

diffs (106 lines):

diff -r 2a466afd922c -r 214e1f1d49c6 security/py-cryptography/Makefile
--- a/security/py-cryptography/Makefile Thu Jul 19 09:10:49 2018 +0000
+++ b/security/py-cryptography/Makefile Thu Jul 19 09:24:37 2018 +0000
@@ -1,6 +1,6 @@
-# $NetBSD: Makefile,v 1.66 2018/04/02 13:19:31 adam Exp $
+# $NetBSD: Makefile,v 1.67 2018/07/19 09:24:37 adam Exp $
 
-DISTNAME=      cryptography-2.2.2
+DISTNAME=      cryptography-2.3
 PKGNAME=       ${PYPKGPREFIX}-${DISTNAME}
 CATEGORIES=    security python
 MASTER_SITES=  ${MASTER_SITE_PYPI:=c/cryptography/}
diff -r 2a466afd922c -r 214e1f1d49c6 security/py-cryptography/distinfo
--- a/security/py-cryptography/distinfo Thu Jul 19 09:10:49 2018 +0000
+++ b/security/py-cryptography/distinfo Thu Jul 19 09:24:37 2018 +0000
@@ -1,6 +1,6 @@
-$NetBSD: distinfo,v 1.52 2018/04/02 13:19:31 adam Exp $
+$NetBSD: distinfo,v 1.53 2018/07/19 09:24:37 adam Exp $
 
-SHA1 (cryptography-2.2.2.tar.gz) = 4e2afea2c84325b9b89ac885ed7b01875d2792db
-RMD160 (cryptography-2.2.2.tar.gz) = 990169925f758a3499c8ea57b17ee4cb028733d7
-SHA512 (cryptography-2.2.2.tar.gz) = 6c1b19cdb870d65abad42523697e9a0bebc7a0025b34f10c4bdd30c313333efd7c41bcb4237a29b3a1b270e3fbade75ccb35df172b055b7c075d619f4d9424c9
-Size (cryptography-2.2.2.tar.gz) = 443822 bytes
+SHA1 (cryptography-2.3.tar.gz) = 2bb0184cab9ac1f78e011d243fbcb039028e79e6
+RMD160 (cryptography-2.3.tar.gz) = 1315cd64f8476d15699cd3908546bc538a38a23f
+SHA512 (cryptography-2.3.tar.gz) = 75e14020da500fdbbd578f004b22ef3237844185329adf59288b29f1b3ee9dd2005a2c4a933fe8609a59d168012a9f687bab0f31ab39ed6ca325198aa9295e52
+Size (cryptography-2.3.tar.gz) = 449464 bytes
diff -r 2a466afd922c -r 214e1f1d49c6 security/py-cryptography_vectors/Makefile
--- a/security/py-cryptography_vectors/Makefile Thu Jul 19 09:10:49 2018 +0000
+++ b/security/py-cryptography_vectors/Makefile Thu Jul 19 09:24:37 2018 +0000
@@ -1,6 +1,6 @@
-# $NetBSD: Makefile,v 1.14 2018/04/02 13:19:31 adam Exp $
+# $NetBSD: Makefile,v 1.15 2018/07/19 09:24:37 adam Exp $
 
-DISTNAME=      cryptography_vectors-2.2.2
+DISTNAME=      cryptography_vectors-2.3
 PKGNAME=       ${PYPKGPREFIX}-${DISTNAME}
 CATEGORIES=    security python
 MASTER_SITES=  ${MASTER_SITE_PYPI:=c/cryptography_vectors/}
diff -r 2a466afd922c -r 214e1f1d49c6 security/py-cryptography_vectors/PLIST
--- a/security/py-cryptography_vectors/PLIST    Thu Jul 19 09:10:49 2018 +0000
+++ b/security/py-cryptography_vectors/PLIST    Thu Jul 19 09:24:37 2018 +0000
@@ -1,4 +1,4 @@
-@comment $NetBSD: PLIST,v 1.7 2018/03/22 11:49:19 adam Exp $
+@comment $NetBSD: PLIST,v 1.8 2018/07/19 09:24:37 adam Exp $
 ${PYSITELIB}/${EGG_INFODIR}/PKG-INFO
 ${PYSITELIB}/${EGG_INFODIR}/SOURCES.txt
 ${PYSITELIB}/${EGG_INFODIR}/dependency_links.txt
@@ -460,6 +460,34 @@
 ${PYSITELIB}/cryptography_vectors/hashes/SHA2/SHA512Monte.rsp
 ${PYSITELIB}/cryptography_vectors/hashes/SHA2/SHA512Monte.txt
 ${PYSITELIB}/cryptography_vectors/hashes/SHA2/SHA512ShortMsg.rsp
+${PYSITELIB}/cryptography_vectors/hashes/SHA2/SHA512_224LongMsg.rsp
+${PYSITELIB}/cryptography_vectors/hashes/SHA2/SHA512_224Monte.rsp
+${PYSITELIB}/cryptography_vectors/hashes/SHA2/SHA512_224Monte.txt
+${PYSITELIB}/cryptography_vectors/hashes/SHA2/SHA512_224ShortMsg.rsp
+${PYSITELIB}/cryptography_vectors/hashes/SHA2/SHA512_256LongMsg.rsp
+${PYSITELIB}/cryptography_vectors/hashes/SHA2/SHA512_256Monte.rsp
+${PYSITELIB}/cryptography_vectors/hashes/SHA2/SHA512_256Monte.txt
+${PYSITELIB}/cryptography_vectors/hashes/SHA2/SHA512_256ShortMsg.rsp
+${PYSITELIB}/cryptography_vectors/hashes/SHA3/SHA3_224LongMsg.rsp
+${PYSITELIB}/cryptography_vectors/hashes/SHA3/SHA3_224Monte.rsp
+${PYSITELIB}/cryptography_vectors/hashes/SHA3/SHA3_224ShortMsg.rsp
+${PYSITELIB}/cryptography_vectors/hashes/SHA3/SHA3_256LongMsg.rsp
+${PYSITELIB}/cryptography_vectors/hashes/SHA3/SHA3_256Monte.rsp
+${PYSITELIB}/cryptography_vectors/hashes/SHA3/SHA3_256ShortMsg.rsp
+${PYSITELIB}/cryptography_vectors/hashes/SHA3/SHA3_384LongMsg.rsp
+${PYSITELIB}/cryptography_vectors/hashes/SHA3/SHA3_384Monte.rsp
+${PYSITELIB}/cryptography_vectors/hashes/SHA3/SHA3_384ShortMsg.rsp
+${PYSITELIB}/cryptography_vectors/hashes/SHA3/SHA3_512LongMsg.rsp
+${PYSITELIB}/cryptography_vectors/hashes/SHA3/SHA3_512Monte.rsp
+${PYSITELIB}/cryptography_vectors/hashes/SHA3/SHA3_512ShortMsg.rsp
+${PYSITELIB}/cryptography_vectors/hashes/SHAKE/SHAKE128LongMsg.rsp
+${PYSITELIB}/cryptography_vectors/hashes/SHAKE/SHAKE128Monte.rsp
+${PYSITELIB}/cryptography_vectors/hashes/SHAKE/SHAKE128ShortMsg.rsp
+${PYSITELIB}/cryptography_vectors/hashes/SHAKE/SHAKE128VariableOut.rsp
+${PYSITELIB}/cryptography_vectors/hashes/SHAKE/SHAKE256LongMsg.rsp
+${PYSITELIB}/cryptography_vectors/hashes/SHAKE/SHAKE256Monte.rsp
+${PYSITELIB}/cryptography_vectors/hashes/SHAKE/SHAKE256ShortMsg.rsp
+${PYSITELIB}/cryptography_vectors/hashes/SHAKE/SHAKE256VariableOut.rsp
 ${PYSITELIB}/cryptography_vectors/hashes/blake2/blake2b.txt
 ${PYSITELIB}/cryptography_vectors/hashes/blake2/blake2s.txt
 ${PYSITELIB}/cryptography_vectors/hashes/ripemd160/ripevectors.txt
@@ -2054,6 +2082,7 @@
 ${PYSITELIB}/cryptography_vectors/x509/PKITS_data/smime/SignedValidpre2000UTCnotBeforeDateTest3.eml
 ${PYSITELIB}/cryptography_vectors/x509/PKITS_data/smime/SignedinhibitAnyPolicyTest3.eml
 ${PYSITELIB}/cryptography_vectors/x509/alternate-rsa-sha1-oid.pem
+${PYSITELIB}/cryptography_vectors/x509/badasn1time.pem
 ${PYSITELIB}/cryptography_vectors/x509/badssl-sct.pem
 ${PYSITELIB}/cryptography_vectors/x509/bigoid.pem
 ${PYSITELIB}/cryptography_vectors/x509/cryptography.io.pem
diff -r 2a466afd922c -r 214e1f1d49c6 security/py-cryptography_vectors/distinfo
--- a/security/py-cryptography_vectors/distinfo Thu Jul 19 09:10:49 2018 +0000
+++ b/security/py-cryptography_vectors/distinfo Thu Jul 19 09:24:37 2018 +0000
@@ -1,6 +1,6 @@
-$NetBSD: distinfo,v 1.14 2018/04/02 13:19:31 adam Exp $
+$NetBSD: distinfo,v 1.15 2018/07/19 09:24:37 adam Exp $
 
-SHA1 (cryptography_vectors-2.2.2.tar.gz) = 902bd2339c2ca02fde5568be34ba6db9ae21ac88
-RMD160 (cryptography_vectors-2.2.2.tar.gz) = 3baa49b197480af73496e9899489869018637b1d
-SHA512 (cryptography_vectors-2.2.2.tar.gz) = bdaf53c8087d6c44fcd3ab54069d1d45b60ee80d98fd813fe180b9e88272203b5dd2abd5fa6dcd3b4ce9ec3215997fd8e99e63309e2f0ac619a6f72d552afff9
-Size (cryptography_vectors-2.2.2.tar.gz) = 27270814 bytes
+SHA1 (cryptography_vectors-2.3.tar.gz) = 275e55bc76d74134c7e3e8ed733f2ca31c19286b
+RMD160 (cryptography_vectors-2.3.tar.gz) = 118062bc683d59ceae6a67c38ed6dc5d96de2cd6
+SHA512 (cryptography_vectors-2.3.tar.gz) = 7c51b0c29c182c4da3265824a1b6e44c943bd41dfa89199cded963d0182a8ade678a560ec9ea13f6e8918119fcacf1c90d804cc90368e51cc5d430228448231c
+Size (cryptography_vectors-2.3.tar.gz) = 35303908 bytes



Home | Main Index | Thread Index | Old Index