From fdbbe046f7b2ac83220f9e61ab03a6be7c37a84a Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 29 Mar 2024 18:28:28 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-BLACK-6256273 - https://snyk.io/vuln/SNYK-PYTHON-FLASK-5490129 - https://snyk.io/vuln/SNYK-PYTHON-JINJA2-6150717 - https://snyk.io/vuln/SNYK-PYTHON-PYDANTIC-5907722 - https://snyk.io/vuln/SNYK-PYTHON-PYDANTIC-5926694 - https://snyk.io/vuln/SNYK-PYTHON-WERKZEUG-3319935 - https://snyk.io/vuln/SNYK-PYTHON-WERKZEUG-3319936 - https://snyk.io/vuln/SNYK-PYTHON-WERKZEUG-6035177 --- requirements.txt | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/requirements.txt b/requirements.txt index 290bd298..72a220a4 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,19 +1,19 @@ attrs==22.1.0 -black==22.8.0 +black==24.3.0 cfgv==3.3.1 click==8.1.3 coverage==6.5.0 distlib==0.3.6 filelock==3.8.0 flasgger==0.9.5 -Flask==2.2.2 +Flask==2.2.5 Flask-SQLAlchemy==3.0.2 freezegun==1.2.2 greenlet==2.0.1 identify==2.5.5 iniconfig==1.1.1 itsdangerous==2.1.2 -Jinja2==3.1.2 +Jinja2==3.1.3 jsonschema==4.17.1 MarkupSafe==2.1.1 mistune==2.0.4 @@ -27,7 +27,7 @@ platformdirs==2.5.2 pluggy==1.0.0 pre-commit==2.20.0 py==1.11.0 -pydantic==1.10.2 +pydantic==1.10.13 PyJWT==2.6.0 PyMySQL==1.0.2 pyparsing==3.0.9 @@ -45,4 +45,4 @@ types-PyMySQL==1.0.19 types-setuptools==65.5.0.3 typing_extensions==4.3.0 virtualenv==20.17.0 -Werkzeug==2.2.2 +Werkzeug==2.3.8