From 73004bc9b1580438363ddfaa77342bc86eeb667b Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sun, 4 May 2025 07:56:44 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-GEVENT-9919772 - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-9964606 --- requirements.txt | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index 7287ffe..e93d943 100644 --- a/requirements.txt +++ b/requirements.txt @@ -45,7 +45,7 @@ fastcache==1.0.2 filelock==3.0.10 Flask==1.0.2 future==0.17.1 -gevent==1.4.0 +gevent==25.4.1 glob2==0.6 greenlet==0.4.15 h5py==2.9.0 @@ -205,3 +205,4 @@ xlwings==0.15.4 xlwt==1.3.0 zict==0.1.4 zipp==0.3.3 +setuptools>=78.1.1 # not directly required, pinned by Snyk to avoid a vulnerability