From 00600287bb002f5e79058b0c82701dff77b33fe8 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 15 Dec 2025 08:01:26 +0000 Subject: [PATCH] fix: requirements/optional_m1_2.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-TORNADO-14400977 - https://snyk.io/vuln/SNYK-PYTHON-TORNADO-14400978 - https://snyk.io/vuln/SNYK-PYTHON-TORNADO-14400979 --- requirements/optional_m1_2.txt | 1 + 1 file changed, 1 insertion(+) diff --git a/requirements/optional_m1_2.txt b/requirements/optional_m1_2.txt index 42a07692d8343..f0fc6ec6b1940 100644 --- a/requirements/optional_m1_2.txt +++ b/requirements/optional_m1_2.txt @@ -12,3 +12,4 @@ pandas pyspark autoflake # for backend generation snakeviz # for profiling +tornado>=6.5.3 # not directly required, pinned by Snyk to avoid a vulnerability