From 08dd473d890cf31c69ee97940aab18eab3ee590d Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 5 Mar 2025 20:12:27 +0000 Subject: [PATCH] fix: requirements_dev.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-6928867 - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-3180412 - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-7448482 - https://snyk.io/vuln/SNYK-PYTHON-SPHINX-570772 - https://snyk.io/vuln/SNYK-PYTHON-SPHINX-570773 - https://snyk.io/vuln/SNYK-PYTHON-SPHINX-5811865 - https://snyk.io/vuln/SNYK-PYTHON-SPHINX-5812109 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-7267250 --- requirements_dev.txt | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/requirements_dev.txt b/requirements_dev.txt index 7e1f54b..e231fea 100644 --- a/requirements_dev.txt +++ b/requirements_dev.txt @@ -5,8 +5,11 @@ watchdog==0.10.2 flake8==3.7.9 tox==3.14.0 coverage==4.5.4 -Sphinx==1.8.5 +Sphinx==3.3.0 twine==3.1.1 pytest==4.6.5 pytest-runner==5.1 +requests>=2.32.2 # not directly required, pinned by Snyk to avoid a vulnerability +setuptools>=70.0.0 # not directly required, pinned by Snyk to avoid a vulnerability +urllib3>=2.2.2 # not directly required, pinned by Snyk to avoid a vulnerability