Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
### Changes This PR: - Bumps the `cryptography` dependency version to `^41.0.5` (up from `^41.0.3`) to address [CVE-2023-45803](https://www.cve.org/CVERecord?id=CVE-2023-45803). - Pins the weak dependency for `urllib3` (by way of `requests`) to `^2.0.7` to address [CVE-2023-5363](https://www.cve.org/CVERecord?id=CVE-2023-5363). ### References N/A ### Testing N/A ### Checklist - [x] I have read the [Auth0 general contribution guidelines](https://github.com/auth0/open-source-template/blob/master/GENERAL-CONTRIBUTING.md) - [x] I have read the [Auth0 Code of Conduct](https://github.com/auth0/open-source-template/blob/master/CODE-OF-CONDUCT.md) - [x] All existing and new tests complete without errors
- Loading branch information