python3Packages.ecdsa has been marked vulnerable, and igvm-tooling depends on it. There won't be a fix to the ecdsa lib, and it isn't likely upstream will move to another dependency as the vulnerability doesn't really affect igvm-tooling's use case. Signed-off-by: Paul Meyer <katexochen0@gmail.com>