From 74a82d5559c5c5162bd3e46edde21c76f6b1cce9 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 23 Feb 2024 18:29:41 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-CERTIFI-5805047 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-5777683 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-5813745 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-5813746 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-5813750 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-5914629 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6036192 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6050294 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6092044 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6126975 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6210214 - https://snyk.io/vuln/SNYK-PYTHON-GITPYTHON-5840584 - https://snyk.io/vuln/SNYK-PYTHON-GITPYTHON-5871282 - https://snyk.io/vuln/SNYK-PYTHON-GITPYTHON-5876644 - https://snyk.io/vuln/SNYK-PYTHON-GITPYTHON-6150683 - https://snyk.io/vuln/SNYK-PYTHON-JINJA2-6150717 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-5918878 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6043904 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6182918 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6219984 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6219986 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-5926907 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-6002459 - https://snyk.io/vuln/SNYK-PYTHON-WERKZEUG-6035177 --- requirements.txt | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/requirements.txt b/requirements.txt index d5e7f2d9..5917821e 100644 --- a/requirements.txt +++ b/requirements.txt @@ -2,12 +2,12 @@ alembic==1.6.5 asn1crypto==0.24.0 Beaker==1.9.0 cached-property==1.5.2 -certifi==2021.5.30 +certifi==2023.7.22 cftime==1.3.1 chardet==3.0.4 click==7.1.2 coards==1.0.5 -cryptography==3.3.2 +cryptography==42.0.2 # pre-installed #Cython==0.27.3 enum34==1.1.6 @@ -20,13 +20,13 @@ Genshi==0.7 GeoAlchemy==0.7.3 GeoAlchemy2==0.9.1 gitdb2==2.0.6 -GitPython==2.1.15 +GitPython==3.1.41 # pre-installed # h5py==2.7.1 idna==2.6 ipaddress==1.0.17 itsdangerous==0.24 -Jinja2==2.11.3 +Jinja2==3.1.3 keyring==10.6.0 keyrings.alt==3.0 Mako==1.1.4 @@ -40,7 +40,7 @@ olefile==0.46 openid2rp==1.12 Paste==2.0.3 pdp-util==1.2.1 -Pillow==4.3.0 +Pillow==10.2.0 ply==3.10 psycopg2==2.7.3.2 pupynere-pdp==1.1.6 @@ -72,8 +72,8 @@ smmap2==3.0.1 SQLAlchemy==1.3.0 sqlparse==0.3.1 static==1.1.1 -urllib3==1.26.5 +urllib3==1.26.18 WebOb==1.7.3 -Werkzeug==0.15.3 +Werkzeug==2.3.8 XlsxWriter==1.0.2 xlwt==1.3.0