summaryrefslogtreecommitdiff
path: root/pkgs/development/python-modules/cryptography (follow)
Commit message (Collapse)AuthorAgeFilesLines
* cryptography: Drop impure host depstoonn2021-11-241-4/+0
| | | | Nix 1.11 has long come and gone. It seems this is no longer necessary.
* pkgs.development.python-modules: remove unused argsMarkus S. Wamser2021-11-122-4/+0
|
* python3Packages.cryptography: 3.4.7 -> 3.4.8Michael Weiss2021-08-242-4/+4
|
* python3Packages.cryptography: add missing libiconv build dependency on darwinIvan Babrou2021-05-191-1/+2
| | | | | | | | | Fixing the following: ``` error: linking with `/nix/store/l3ca456ppdy8hi9hc0rvyr6mrm76si08-clang-wrapper-11.1.0/bin/cc` failed: exit code: 1 = note: ld: library not found for -liconv ```
* python3Packages.cryptography: ignore test_openssl_memleak.py on aarch64-darwinIvan Babrou2021-05-171-1/+11
| | | | The test fails due to dependency on W+X memory, which is forbidden as of 11.2.
* python3Packages.cryptography: Update Cargo hashAlex Wied2021-04-161-1/+1
|
* python3Packages.cryptography: 3.4.6 -> 3.4.7Michael Weiss2021-03-262-4/+4
|
* pypy3.pkgs.cryptography: fix buildFrederik Rietdijk2021-03-131-0/+1
| | | | setuptools-rust was accidentally added to the wrong list.
* python3Packages.cryptography: 3.4.5 -> 3.4.6Michael Weiss2021-02-172-4/+4
|
* python3Packages.cryptography: 3.4.4 -> 3.4.5Michael Weiss2021-02-142-4/+4
|
* python3Packages.cryptography: 3.4.2 -> 3.4.4Michael Weiss2021-02-112-4/+4
| | | | Contains a few minor fixes and improvements.
* python3Packages.cryptography: 3.3.2 -> 3.4.2Michael Weiss2021-02-102-9/+19
| | | | | | | | | | | Backwards incompatible changes: Support for Python 2 has been removed. Note: This isn't a problem for Nixpkgs because pythonPackages.cryptography is frozen at version 3.3.2. Other important packaging changes: "Cryptography now incorporates Rust code. Users building cryptography themselves will need to have the Rust toolchain installed. Users who use an officially produced wheel will not need to make any changes. The minimum supported Rust version is 1.45.0."
* python3Packages.cryptography: 3.3.1 -> 3.3.2 (security, CVE-2020-36242)Michael Weiss2021-02-074-6/+6
| | | | | | | | | SECURITY ISSUE: Fixed a bug where certain sequences of update() calls when symmetrically encrypting very large payloads (>2GB) could result in an integer overflow, leading to buffer overflows. CVE-2020-36242 Note: This also updates {,vectors-}3.3.nix (for Python 2 / nixops) because of the security issue.
* pkgs/development/python-modules: stdenv.lib -> libPavol Rusnak2021-01-242-8/+8
|
* treewide: with stdenv.lib; in meta -> with lib;Profpatsch2021-01-112-4/+4
| | | | | | | | | | | | | | | | | | | Part of: https://github.com/NixOS/nixpkgs/issues/108938 meta = with stdenv.lib; is a widely used pattern. We want to slowly remove the `stdenv.lib` indirection and encourage people to use `lib` directly. Thus let’s start with the meta field. This used a rewriting script to mostly automatically replace all occurances of this pattern, and add the `lib` argument to the package header if it doesn’t exist yet. The script in its current form is available at https://cs.tvl.fyi/depot@2f807d7f141068d2d60676a89213eaa5353ca6e0/-/blob/users/Profpatsch/nixpkgs-rewriter/default.nix
* Merge staging-next into staginggithub-actions[bot]2020-12-144-82/+27
|\
| * python2Packages.cryptography: 2.9.2 -> 3.3.1 (#106792)Orivej Desh2020-12-144-82/+27
| | | | | | | | Fixes py2 build of pyOpenSSL: https://github.com/NixOS/nixpkgs/issues/106275#issuecomment-743790876
* | python3Packages.cryptography: 3.2.1 -> 3.3.1Michael Weiss2020-12-102-3/+3
|/ | | | | | | | | | | | | | | | | | Backward incompatible changes: - Support for Python 3.5 has been removed due to low usage and maintenance burden. - The GCM and AESGCM now require 64-bit to 1024-bit (8 byte to 128 byte) initialization vectors. This change is to conform with an upcoming OpenSSL release that will no longer support sizes outside this window. - When deserializing asymmetric keys we now raise ValueError rather than UnsupportedAlgorithm when an unsupported cipher is used. This change is to conform with an upcoming OpenSSL release that will no longer distinguish between error types. - We no longer allow loading of finite field Diffie-Hellman parameters of less than 512 bits in length. This change is to conform with an upcoming OpenSSL release that no longer supports smaller sizes. These keys were already wildly insecure and should not have been used in any application outside of testing.
* python2.pkgs.cryptography: Fix CVE-2020-25659adisbladis2020-12-042-1/+78
| | | | This patch is from Ubuntu 20.04's backport.
* Merge master into staging-nextFrederik Rietdijk2020-11-271-0/+1
|\
| * python2Packages.cryptography: mark insecure, CVE-2020-25659Jonathan Ringer2020-11-241-0/+1
| |
* | pythonPackages.cffi: cffi is a native build input as wellFrederik Rietdijk2020-11-191-2/+9
|/
* python3Packages.cryptography: 3.2 -> 3.2.1Michael Weiss2020-10-292-3/+3
| | | | | | Changelog: - Disable blinding on RSA public keys to address an error with some versions of OpenSSL.
* python3Packages.cryptography: 3.1.1 -> 3.2 (security, CVE-2020-25659)Michael Weiss2020-10-262-3/+3
| | | | | | | | | SECURITY ISSUE: Attempted to make RSA PKCS#1v1.5 decryption more constant time, to protect against Bleichenbacher vulnerabilities. Due to limitations imposed by our API, we cannot completely mitigate this vulnerability and a future release will contain a new API which is designed to be resilient to these for contexts where it is required. Credit to Hubert Kario for reporting the issue. CVE-2020-25659
* python3Packages.cryptography: 3.1 -> 3.1.1Michael Weiss2020-09-222-3/+3
|
* python3Packages.cryptography: 3.0 -> 3.1Michael Weiss2020-08-292-3/+3
| | | | | | | Backwards incompatible changes: - Removed support for idna based U-label parsing in various X.509 classes. This support was originally deprecated in version 2.1 and moved to an extra in 2.5.
* python2Packages.cryptography-vectors: pin at 2.9.2Jonathan Ringer2020-08-091-0/+23
|
* python2Packages.cryptography: pin to 2.9.2Jonathan Ringer2020-08-091-0/+74
|
* python3Packages.cryptography: 2.9.2 -> 3.0Michael Weiss2020-07-222-3/+3
| | | | | | | | | | | | | | | | | | | | | Backwards incompatible changes: - Removed support for passing an Extension instance to from_issuer_subject_key_identifier(), as per our deprecation policy. - Support for LibreSSL 2.7.x, 2.8.x, and 2.9.0 has been removed (2.9.1+ is still supported). - Dropped support for macOS 10.9, macOS users must upgrade to 10.10 or newer. - RSA generate_private_key() no longer accepts public_exponent values except 65537 and 3 (the latter for legacy purposes). - X.509 certificate parsing now enforces that the version field contains a valid value, rather than deferring this check until version is accessed. Deprecations: - Deprecated support for Python 2. At the time there is no time table for actually dropping support, however we strongly encourage all users to upgrade their Python, as Python 2 no longer receives support from the Python core team.
* treewide: replace SRI hashesDaiderd Jordan2020-06-011-1/+1
|
* python.pkgs.cryptography_vectors: 2.9.1 -> 2.9.2Frederik Rietdijk2020-05-111-1/+1
|
* python3Packages.cryptography: 2.9.1 -> 2.9.2Frederik Rietdijk2020-05-111-2/+2
|
* python3Packages.cryptography: 2.9 -> 2.9.1Michael Weiss2020-04-222-3/+3
| | | | | "Updated Windows, macOS, and ``manylinux`` wheels to be compiled with OpenSSL 1.1.1g."
* python2.pkgs.cryptography: fixup build of dependantsVladimír Čunát2020-04-181-1/+2
| | | | | ... most notably fix pyopenssl. I can't say I really understand this, but the commit seems safe enough.
* python2Packages.cryptography: add missing ipaddress dependencyJonathan Ringer2020-04-101-1/+4
|
* python3Packages.cryptography: 2.8 -> 2.9Michael Weiss2020-04-052-13/+10
| | | | | | | | | | | | | | | Backwards incompatible changes: - Support for Python 3.4 has been removed due to low usage and maintenance burden. - Support for OpenSSL 1.0.1 has been removed. Users on older version of OpenSSL will need to upgrade. - Support for LibreSSL 2.6.x has been removed. - Reversed the order in which rfc4514_string() returns the RDNs as required by RFC 4514. Note: The first three changes should have no impact on Nixpkgs as we already removed Python 3.4 and OpenSSL 1.0.1. Additionally we don't support LibreSSL for this package.
* python37Packages.cryptography: 2.7 -> 2.8Michael Weiss2019-10-202-12/+3
| | | | | | | | | | | Changelog: https://cryptography.io/en/latest/changelog/#v2-8 Important changes: - Deprecated support for OpenSSL 1.0.1. Support will be removed in cryptography 2.9. - cryptography no longer depends on asn1crypto. - Added support for Python 3.8.
* python.pkgs.cryptography: fix/ignore broken testsRobin Gloster2019-09-131-1/+10
| | | | | | Broken tests by openssl 1.1.1d, added patch and skipped one test Issue for skipped test: https://github.com/pyca/cryptography/issues/4998
* python37Packages.cryptography: 2.6.1 -> 2.7Michael Weiss2019-05-312-3/+3
| | | | | | | | | | | | | Changelog: https://cryptography.io/en/latest/changelog/#v2-7 Important changes: - BACKWARDS INCOMPATIBLE: We no longer distribute 32-bit manylinux1 wheels. Continuing to produce them was a maintenance burden. - BACKWARDS INCOMPATIBLE: Removed the cryptography.hazmat.primitives.mac.MACContext interface. The CMAC and HMAC APIs have not changed, but they are no longer registered as MACContext instances.
* Merge pull request #56744 from matthewbauer/macos-10-12Matthew Bauer2019-04-261-8/+0
|\ | | | | Update macOS to 10.12
| * pycrypto: remove pre-10.12 patchMatthew Bauer2019-04-261-8/+0
| |
* | pythonPackages.cryptography: vectors are checkInputsworldofpeace2019-04-221-4/+5
| |
* | python37Packages.cryptography: 2.5 -> 2.6.1Michael Weiss2019-04-222-3/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Changelog: https://cryptography.io/en/latest/changelog/#v2-6-1 Important changes: - BACKWARDS INCOMPATIBLE: Removed cryptography.hazmat.primitives.asymmetric.utils.encode_rfc6979_signature and cryptography.hazmat.primitives.asymmetric.utils.decode_rfc6979_signature, which had been deprecated for nearly 4 years. Use encode_dss_signature() and decode_dss_signature() instead. - BACKWARDS INCOMPATIBLE: Removed cryptography.x509.Certificate.serial, which had been deprecated for nearly 3 years. Use serial_number instead.
* | python37Packages.cryptography: Improve the test vectors integrationMichael Weiss2019-04-222-2/+24
|/ | | | | | | This should make the management easier. The package cryptography_vectors contains the test vectors for cryptography and should therefore always have the same version. By linking the version of cryptography_vectors to cryptography, this simply cannot be forgotten.
* python37Packages.cryptography: 2.4.2 -> 2.5Michael Weiss2019-02-141-4/+2
| | | | | | | | | | Changelog: https://cryptography.io/en/latest/changelog/#v2-5 Important changes: - BACKWARDS INCOMPATIBLE: U-label strings were deprecated in version 2.1, but this version removes the default idna dependency as well. - BACKWARDS INCOMPATIBLE: The minimum supported PyPy version is now 5.4.
* Merge remote-tracking branch 'NixOS/master' into stagingMatthew Bauer2019-01-271-0/+14
|\
| * python37Packages.cryptography: Add meta-attributesMichael Weiss2019-01-241-0/+14
| |
* | python37Packages.cryptography: 2.3.1 -> 2.4.2Michael Weiss2019-01-141-2/+2
|/ | | | | | | | | | | | Changelog: https://cryptography.io/en/latest/changelog/#v2-4-2 Important changes: - BACKWARDS INCOMPATIBLE: Dropped support for LibreSSL 2.4.x. - Deprecated OpenSSL 1.0.1 support. OpenSSL 1.0.1 is no longer supported by the OpenSSL project. At this time there is no time table for dropping support, however we strongly encourage all users to upgrade or install cryptography from a wheel.
* pythonPackages.cryptography: ignore pytest warningsFrederik Rietdijk2018-11-111-0/+4
| | | | | The test suite was generating a lot of warnings, causing the hydra build to fail. Unfortunately, PYTHONWARNINGS env var is completely ignored.
* python: cryptography: 2.3 -> 2.3.1Frederik Rietdijk2018-08-251-2/+2
|