Skip to main content

Pinned dependencies for high-security environments

Project description

Pinned dependencies for high-security environments

The aegisx.ext.cve package is designed to enhance the security of your AegisX environment by providing curated dependency pinning that excludes known vulnerabilities (CVEs) from the dependency tree.

By default, AegisX avoids pinning dependencies across its packages to maintain backward compatibility and allow implementers to apply their own security policies. The aegisx.ext.cve package overrides this behavior, ensuring that all dependencies are locked to versions free from known security flaws. This package is particularly recommended for high-security environments where stricter control over vulnerabilities is essential.

Changelog

0.0.1

  • CVE-2024-12797 Pin cryptography>=0.44.0
  • CVE-2024-47874 Pin starlette>=0.40.0 in the fastapi extra.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

aegisx_ext_cve-0.0.1.tar.gz (2.5 kB view details)

Uploaded Source

File details

Details for the file aegisx_ext_cve-0.0.1.tar.gz.

File metadata

  • Download URL: aegisx_ext_cve-0.0.1.tar.gz
  • Upload date:
  • Size: 2.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.12.9

File hashes

Hashes for aegisx_ext_cve-0.0.1.tar.gz
Algorithm Hash digest
SHA256 7f0713a6e0fee7a7e57a42f266a004aa3f1299356762cfef1b207a46945f0bcf
MD5 ee0708e6982c765e31d344d646c40574
BLAKE2b-256 2d81d515853a0dd4453c9fe9817b766070c7be9134a1c241ae23533964065001

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page