From a252c50f8c976862fee1b70b37cc8d853b869b6e Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 2 Apr 2026 21:38:51 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-H11-10293728 - https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-10305723 - https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-15763443 - https://snyk.io/vuln/SNYK-PYTHON-STARLETTE-10874054 - https://snyk.io/vuln/SNYK-PYTHON-STARLETTE-13733964 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-10390193 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-10390194 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-14192442 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-14192443 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-14896210 --- requirements.txt | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/requirements.txt b/requirements.txt index 5c2814f..f6aad68 100644 --- a/requirements.txt +++ b/requirements.txt @@ -6,7 +6,7 @@ certifi==2025.1.31 charset-normalizer==3.4.1 click==8.1.8 fastapi==0.115.12 -h11==0.14.0 +h11==0.16.0 httpcore==1.0.7 httpx==0.28.1 idna==3.10 @@ -21,12 +21,12 @@ pydantic_core==2.27.2 pytest==8.3.5 python-dateutil==2.9.0.post0 python-dotenv==1.0.1 -requests==2.32.3 +requests==2.33.0 s3transfer==0.11.4 six==1.17.0 sniffio==1.3.1 SQLAlchemy==2.0.39 -starlette==0.46.1 +starlette==0.49.1 typing_extensions==4.12.2 -urllib3==2.3.0 +urllib3==2.6.3 uvicorn==0.34.0