Hi Apache Beam Team, We recently evaluated Apache Beam 2.76.0 for Python and noticed that the release currently restricts the `cryptography` dependency to versions earlier than 49.0.0.
Our organization uses Snyk for vulnerability management, and Snyk reports known security vulnerabilities in versions of `cryptography` below 49.0.0. As a result, we are unable to adopt Apache Beam 2.76.0 in our environment. This issue may also affect other organizations with similar security compliance requirements. Could you please help clarify the following: 1. Is it possible to address this issue through a security-focused patch release that supports a non-vulnerable version of the `cryptography` package? 2. For future releases, could the project consider incorporating dependency vulnerability reviews and remediation as part of the release process to help minimize exposure to known CVEs? 3. 4. For reference, the Snyk vulnerability report is available here: 5. 6. https://security.snyk.io/package/pip/cryptography/versions 7. 8. 9. Thank you for your time and assistance. Thanks Arun
