From e4100d7dabf02b714f13d8db3bf89ba01748bdeb Mon Sep 17 00:00:00 2001 From: "snyk-io[bot]" <141718529+snyk-io[bot]@users.noreply.github.com> Date: Fri, 6 Sep 2024 23:17:38 -0400 Subject: [PATCH 1/2] fix: dev-requirements.txt to reduce vulnerabilities (#16) The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-6928867 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-7267250 - https://snyk.io/vuln/SNYK-PYTHON-WERKZEUG-6035177 - https://snyk.io/vuln/SNYK-PYTHON-WERKZEUG-6808933 - https://snyk.io/vuln/SNYK-PYTHON-ZIPP-7430899 Co-authored-by: snyk-io[bot] <141718529+snyk-io[bot]@users.noreply.github.com> --- dev-requirements.txt | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/dev-requirements.txt b/dev-requirements.txt index 16ef181806a..768db3100b4 100644 --- a/dev-requirements.txt +++ b/dev-requirements.txt @@ -22,3 +22,7 @@ pytest-factoryboy==2.7.0 pytest-freezegun==0.4.2 pytest-rerunfailures==14.0 pytest-split==0.9.0 +requests>=2.32.2 # not directly required, pinned by Snyk to avoid a vulnerability +urllib3>=2.2.2 # not directly required, pinned by Snyk to avoid a vulnerability +werkzeug>=3.0.3 # not directly required, pinned by Snyk to avoid a vulnerability +zipp>=3.19.1 # not directly required, pinned by Snyk to avoid a vulnerability From 623aabeefc0cc13520ffbd918dffed196fc61a9d Mon Sep 17 00:00:00 2001 From: "snyk-io[bot]" <141718529+snyk-io[bot]@users.noreply.github.com> Date: Wed, 30 Oct 2024 17:30:18 +0000 Subject: [PATCH 2/2] fix: dev-requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-WERKZEUG-8309091 - https://snyk.io/vuln/SNYK-PYTHON-WERKZEUG-8309092 --- dev-requirements.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/dev-requirements.txt b/dev-requirements.txt index 768db3100b4..75d5654deae 100644 --- a/dev-requirements.txt +++ b/dev-requirements.txt @@ -24,5 +24,5 @@ pytest-rerunfailures==14.0 pytest-split==0.9.0 requests>=2.32.2 # not directly required, pinned by Snyk to avoid a vulnerability urllib3>=2.2.2 # not directly required, pinned by Snyk to avoid a vulnerability -werkzeug>=3.0.3 # not directly required, pinned by Snyk to avoid a vulnerability +werkzeug>=3.0.6 # not directly required, pinned by Snyk to avoid a vulnerability zipp>=3.19.1 # not directly required, pinned by Snyk to avoid a vulnerability