From 86ef494231cb84b7c3956bb01466f2c257eaafef Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 31 Jul 2024 07:50:16 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-JINJA2-6150717 - https://snyk.io/vuln/SNYK-PYTHON-JINJA2-6809379 - https://snyk.io/vuln/SNYK-PYTHON-ZIPP-7430899 --- requirements.txt | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index b2330b7..861a803 100644 --- a/requirements.txt +++ b/requirements.txt @@ -6,10 +6,11 @@ Flask-Caching==2.0.2 gevent==21.12.0 html5lib==1.1 itsdangerous==2.1.2 -Jinja2==3.1.2 +Jinja2==3.1.4 MarkupSafe==2.1.3 misaka==2.1.1 pytest==7.4.1 pytest-cov==4.1.0 Werkzeug==2.3.6 setuptools>=65.5.1 # not directly required, pinned by Snyk to avoid a vulnerability +zipp>=3.19.1 # not directly required, pinned by Snyk to avoid a vulnerability