From 691213353af9c1c157a9d0c13e68060dc6ecf173 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 5 Aug 2024 07:21:02 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-ASTROPY-6457316 - https://snyk.io/vuln/SNYK-PYTHON-BLEACH-1069893 - https://snyk.io/vuln/SNYK-PYTHON-BLEACH-552160 - https://snyk.io/vuln/SNYK-PYTHON-BLEACH-561119 - https://snyk.io/vuln/SNYK-PYTHON-BLEACH-561754 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-1022152 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3172287 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3314966 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3315324 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3315328 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3315331 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3315452 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3315972 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3315975 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3316038 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3316211 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-5663682 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-5777683 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-5813745 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-5813746 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-5813750 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-5914629 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6036192 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6050294 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6126975 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6210214 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6913422 - https://snyk.io/vuln/SNYK-PYTHON-IPYTHON-2348630 - https://snyk.io/vuln/SNYK-PYTHON-IPYTHON-3318382 - https://snyk.io/vuln/SNYK-PYTHON-JINJA2-1012994 - https://snyk.io/vuln/SNYK-PYTHON-JINJA2-174126 - https://snyk.io/vuln/SNYK-PYTHON-JINJA2-6150717 - https://snyk.io/vuln/SNYK-PYTHON-JINJA2-6809379 - https://snyk.io/vuln/SNYK-PYTHON-JUPYTERCORE-3063766 - https://snyk.io/vuln/SNYK-PYTHON-JUPYTERLAB-1537939 - https://snyk.io/vuln/SNYK-PYTHON-JUPYTERLAB-6182923 - https://snyk.io/vuln/SNYK-PYTHON-MISTUNE-2940625 - https://snyk.io/vuln/SNYK-PYTHON-NBCONVERT-2979829 - https://snyk.io/vuln/SNYK-PYTHON-NOTEBOOK-1041707 - https://snyk.io/vuln/SNYK-PYTHON-NOTEBOOK-1567195 - https://snyk.io/vuln/SNYK-PYTHON-NOTEBOOK-2441824 - https://snyk.io/vuln/SNYK-PYTHON-NOTEBOOK-2928995 - https://snyk.io/vuln/SNYK-PYTHON-NUMPY-2321964 - https://snyk.io/vuln/SNYK-PYTHON-NUMPY-2321966 - https://snyk.io/vuln/SNYK-PYTHON-NUMPY-2321969 - https://snyk.io/vuln/SNYK-PYTHON-NUMPY-2321970 - https://snyk.io/vuln/SNYK-PYTHON-NUMPY-73513 - https://snyk.io/vuln/SNYK-PYTHON-PROMPTTOOLKIT-6141120 - https://snyk.io/vuln/SNYK-PYTHON-PYGMENTS-1086606 - https://snyk.io/vuln/SNYK-PYTHON-PYGMENTS-1088505 - https://snyk.io/vuln/SNYK-PYTHON-PYGMENTS-5750273 - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-3180412 - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-7448482 - https://snyk.io/vuln/SNYK-PYTHON-TORNADO-5537286 - https://snyk.io/vuln/SNYK-PYTHON-TORNADO-5840803 - https://snyk.io/vuln/SNYK-PYTHON-TORNADO-6041512 - https://snyk.io/vuln/SNYK-PYTHON-TORNADO-7217828 - https://snyk.io/vuln/SNYK-PYTHON-TORNADO-7217829 --- requirements.txt | 29 +++++++++++++++-------------- 1 file changed, 15 insertions(+), 14 deletions(-) diff --git a/requirements.txt b/requirements.txt index 7287ffe..dd0eea6 100644 --- a/requirements.txt +++ b/requirements.txt @@ -4,7 +4,7 @@ anaconda-navigator==1.9.7 anaconda-project==0.8.2 asn1crypto==0.24.0 astroid==2.2.5 -astropy==3.1.2 +astropy==5.3.3 atomicwrites==1.3.0 attrs==19.1.0 Babel==2.6.0 @@ -14,7 +14,7 @@ backports.shutil-get-terminal-size==1.0.0 beautifulsoup4==4.7.1 bitarray==0.8.3 bkcharts==0.2 -bleach==3.1.0 +bleach==3.3.0 bokeh==1.0.4 boto==2.49.0 Bottleneck==1.2.1 @@ -30,7 +30,7 @@ conda==4.6.11 conda-build==3.17.8 conda-verify==3.1.1 contextlib2==0.5.5 -cryptography==2.6.1 +cryptography==42.0.8 cycler==0.10.0 Cython==0.29.6 cytoolz==0.9.0.1 @@ -56,20 +56,20 @@ imageio==2.5.0 imagesize==1.1.0 importlib-metadata==0.0.0 ipykernel==5.1.0 -ipython==7.4.0 +ipython==8.10.0 ipython-genutils==0.2.0 ipywidgets==7.4.2 isort==4.3.16 itsdangerous==1.1.0 jdcal==1.4 jedi==0.13.3 -Jinja2==2.10 +Jinja2==3.1.4 jsonschema==3.0.1 jupyter==1.0.0 jupyter-client==5.2.4 jupyter-console==6.0.0 -jupyter-core==4.4.0 -jupyterlab==0.35.4 +jupyter-core==4.11.2 +jupyterlab==3.6.7 jupyterlab-server==0.2.0 keyring==18.0.0 kiwisolver==1.0.1 @@ -82,7 +82,7 @@ MarkupSafe==1.1.1 matplotlib==3.0.3 mccabe==0.6.1 menuinst==1.4.16 -mistune==0.8.4 +mistune==2.0.3 mkl-fft==1.0.10 mkl-random==1.0.2 more-itertools==6.0.0 @@ -90,15 +90,15 @@ mpmath==1.1.0 msgpack==0.6.1 multipledispatch==0.6.0 navigator-updater==0.2.1 -nbconvert==5.4.1 +nbconvert==6.3.0b0 nbformat==4.4.0 networkx==2.2 nltk==3.4 nose==1.3.7 -notebook==5.7.8 +notebook==6.4.12 numba==0.43.1 numexpr==2.6.9 -numpy==1.16.2 +numpy==1.22.2 numpydoc==0.8.0 oauthlib==3.0.1 olefile==0.46 @@ -118,7 +118,7 @@ pkginfo==1.5.0.1 pluggy==0.9.0 ply==3.11 prometheus-client==0.6.0 -prompt-toolkit==2.0.9 +prompt-toolkit==3.0.13 psutil==5.6.1 py==1.8.0 pycodestyle==2.5.0 @@ -127,7 +127,7 @@ pycparser==2.19 pycrypto==2.6.1 pycurl==7.43.0.2 pyflakes==2.1.1 -Pygments==2.3.1 +Pygments==2.15.0 pylint==2.3.1 pyodbc==4.0.26 pyOpenSSL==19.0.0 @@ -184,7 +184,7 @@ tblib==1.3.2 terminado==0.8.1 testpath==0.4.2 toolz==0.9.0 -tornado==6.0.2 +tornado==6.4.1 tqdm==4.31.1 traitlets==4.3.2 typed-ast==1.3.5 @@ -205,3 +205,4 @@ xlwings==0.15.4 xlwt==1.3.0 zict==0.1.4 zipp==0.3.3 +setuptools>=70.0.0 # not directly required, pinned by Snyk to avoid a vulnerability