From 7bea952c724319d164ae153b2e6ff769c3aecb43 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 19 Jun 2024 04:22:56 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6913422 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-7267250 --- requirements.txt | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/requirements.txt b/requirements.txt index 1678448..50ab755 100644 --- a/requirements.txt +++ b/requirements.txt @@ -3,7 +3,7 @@ certifi==2020.4.5.1 cffi==1.14.0 chardet==3.0.4 click==7.1.1 -cryptography==3.3.2 +cryptography==42.0.8 idna==2.9 importlib-metadata==1.6.0 jeepney==0.4.3 @@ -15,5 +15,5 @@ PyNaCl==1.3.0 requests==2.23.0 SecretStorage==3.1.2 six==1.14.0 -urllib3==1.25.9 +urllib3==1.26.19 zipp==3.1.0