HBASE-26821 Bump dependencies in /dev-support/git-jira-release-audit (#4193)
commitaddace21b6e257182a65546e5580f32ee51489a7
authorAndrew Purtell <apurtell@apache.org>
Thu, 10 Mar 2022 20:25:33 +0000 (10 12:25 -0800)
committerGitHub <noreply@github.com>
Thu, 10 Mar 2022 20:25:33 +0000 (10 12:25 -0800)
tree0dc587818aca037f4b9d95b052f1d7156bc1dcc2
parente5dbbd20ac87ee3983ac8a6057bf14c2f04d02ac
HBASE-26821 Bump dependencies in /dev-support/git-jira-release-audit (#4193)

Bumps urllib3 from 1.25.8 to 1.26.5 to resolve two dependabot warnings

  CRLF injection (Moderate)
  urllib3 (pip) · dev-support/git-jira-release-audit/requirements.txt

  Catastrophic backtracking in URL authority parser when passed URL containing many @ characters (High)
  urllib3 (pip) · dev-support/git-jira-release-audit/requirements.txt

Bumps cryptography from 2.8 to 3.3.2 to resolve one dependabot warning

  RSA decryption vulnerable to Bleichenbacher timing vulnerability (Moderate)
  cryptography (pip) · dev-support/git-jira-release-audit/requirements.txt

Signed-off-by: Duo Zhang <zhangduo@apache.org>
Signed-off-by: Nick Dimiduk <ndimiduk@apache.org>
Signed-off-by: Wei-Chiu Chuang <weichiu@apache.org>
dev-support/git-jira-release-audit/requirements.txt