summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorJoffrey F <f.joffrey@gmail.com>2018-10-17 14:25:08 -0700
committerGitHub <noreply@github.com>2018-10-17 14:25:08 -0700
commit8820e737c6bb18db575a7a57c52cf061790be543 (patch)
tree3eb6a902ee0bac11bc7d89b2cc81be2512feddfd
parent567d552699e99ec26f6095339369549bf6d51fcc (diff)
parent609045f343ac628f953bb3a8fe5b201700929b5c (diff)
downloaddocker-py-8820e737c6bb18db575a7a57c52cf061790be543.tar.gz
Merge pull request #2155 from docker/bump_pyopenssl
Bump pyopenssl to prevent installation of vulnerable version
-rw-r--r--requirements.txt2
-rw-r--r--setup.py2
2 files changed, 2 insertions, 2 deletions
diff --git a/requirements.txt b/requirements.txt
index 289dea9..c46a021 100644
--- a/requirements.txt
+++ b/requirements.txt
@@ -10,7 +10,7 @@ idna==2.5
ipaddress==1.0.18
packaging==16.8
pycparser==2.17
-pyOpenSSL==17.0.0
+pyOpenSSL==18.0.0
pyparsing==2.2.0
pypiwin32==219; sys_platform == 'win32' and python_version < '3.6'
pypiwin32==223; sys_platform == 'win32' and python_version >= '3.6'
diff --git a/setup.py b/setup.py
index 1b208e5..390783d 100644
--- a/setup.py
+++ b/setup.py
@@ -40,7 +40,7 @@ extras_require = {
# https://github.com/pypa/pip/issues/4391). Once that's fixed, instead of
# installing the extra dependencies, install the following instead:
# 'requests[security] >= 2.5.2, != 2.11.0, != 2.12.2'
- 'tls': ['pyOpenSSL>=0.14', 'cryptography>=1.3.4', 'idna>=2.0.0'],
+ 'tls': ['pyOpenSSL>=17.5.0', 'cryptography>=1.3.4', 'idna>=2.0.0'],
}