Conversation
The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-FLASK-15322678 - https://snyk.io/vuln/SNYK-PYTHON-WERKZEUG-15322677
|
This is a major version upgrade for both Flask and its core dependency, Werkzeug. The upgrade introduces significant breaking changes that require code modifications and thorough testing. Key Breaking Changes: Flask (2.2.5 → 3.1.3):
Werkzeug (2.2.3 → 3.1.6):
Recommendation: This upgrade requires developer action. Pay close attention to password verification logic if using Source: Flask Changelog, Werkzeug Changelog
|
Snyk has created this PR to fix 2 vulnerabilities in the pip dependencies of this project.
Snyk changed the following file(s):
example/requirements.txtBreaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.