From eed4f234f108d1e21e64f51d2435c799eb06745a Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Tue, 4 Jun 2024 22:18:14 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-CERTIFI-3164749 - https://snyk.io/vuln/SNYK-PYTHON-CERTIFI-5805047 - https://snyk.io/vuln/SNYK-PYTHON-IDNA-6597975 - https://snyk.io/vuln/SNYK-PYTHON-JINJA2-6150717 - https://snyk.io/vuln/SNYK-PYTHON-JINJA2-6809379 - https://snyk.io/vuln/SNYK-PYTHON-MAKO-3017600 - https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-5595532 --- requirements.txt | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index 2dfe14110d..e05523dce9 100644 --- a/requirements.txt +++ b/requirements.txt @@ -10,7 +10,7 @@ passlib==1.7.2 bcrypt==3.1.7 six==1.13.0 itsdangerous==1.1.0 -requests>=2.20.0 +requests>=2.31.0 PyMySQL==0.9.3 gunicorn==19.9.0 normality==2.0.0 @@ -27,3 +27,7 @@ flask-marshmallow==0.10.1 marshmallow-sqlalchemy==0.17.0 boto3==1.10.39 marshmallow==2.20.2 +certifi>=2023.7.22 # not directly required, pinned by Snyk to avoid a vulnerability +idna>=3.7 # not directly required, pinned by Snyk to avoid a vulnerability +jinja2>=3.1.4 # not directly required, pinned by Snyk to avoid a vulnerability +mako>=1.2.2 # not directly required, pinned by Snyk to avoid a vulnerability