-
Notifications
You must be signed in to change notification settings - Fork 1.1k
Open
Description
What is your suggestion?
Hi,
in order to use conan
in environments that are strict with regard to security concerns it would be great to have a less restrictive bound on the urllib
, which is currently bound to < 2.1
, but CVE-2024-37891 exists for versions smaller than 2.2.2
.
I will create a pull request expanding the allowed range of versions a little, but I don't know how you evaluate that all versions within that range work as expected and would appreciate your help to allow for newer versions.
Thanks in advance!
Have you read the CONTRIBUTING guide?
- I've read the CONTRIBUTING guide
Metadata
Metadata
Assignees
Labels
No labels