From 96f5400b70c4a09afdff8b8b728e44048ac810c6 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 14 Jul 2025 19:08:26 +0000 Subject: [PATCH] fix: cvat/requirements/base.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-PROTOBUF-10364902 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-10390193 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-10390194 --- cvat/requirements/base.txt | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/cvat/requirements/base.txt b/cvat/requirements/base.txt index 0b8781152cc2..af2ea9a4ec8c 100644 --- a/cvat/requirements/base.txt +++ b/cvat/requirements/base.txt @@ -49,6 +49,7 @@ google-cloud-storage==1.42.0 # --no-binary=datumaro: workaround for pip to install # opencv-headless instead of regular opencv, to actually run setup script datumaro==0.2.0 --no-binary=datumaro -urllib3>=1.26.5 # not directly required, pinned by Snyk to avoid a vulnerability +urllib3>=2.5.0 # not directly required, pinned by Snyk to avoid a vulnerability natsort==8.0.0 mistune>=2.0.1 # not directly required, pinned by Snyk to avoid a vulnerability +protobuf>=4.25.8 # not directly required, pinned by Snyk to avoid a vulnerability