Skip to content

Dependencies/backends: Require cryptography - #423

Open
houzefa-abba wants to merge 1 commit into
mpdavis:masterfrom
houzefa-abba:require-cryptography
Open

houzefa-abba wants to merge 1 commit into
mpdavis:masterfrom
houzefa-abba:require-cryptography

Conversation

@houzefa-abba

Copy link
Copy Markdown

Remove dependencies on ecdsa, pyasn1, rsa.
cryptography is now a required dependency.
Remove non-cryptography backends.

In the process, also fix a non-initialized instance of CryptographyEc.SECP256 in test_incorrect_public_key_hmac_signing.


This is an opinionated PR, hence version bump to 4.0.0.

I know python-jose was working fine with optional backends, but doing this simplifies packaging / security analysis by a lot.
Non-cryptography backend deps are obsolete anyway:


#400 is a similar PR but it only removes ecdsa; mine goes further.

Remove dependencies on ecdsa, pyasn1, rsa.
cryptography is now a required dependency.
Remove non-cryptography backends.

In the process, also fix a non-initialized instance of
CryptographyEc.SECP256 in test_incorrect_public_key_hmac_signing.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant