From 979c5eed9adf02fbdd2a778287cb8325b38d8abe Mon Sep 17 00:00:00 2001 From: ubiquitin Date: Wed, 22 Jan 2020 04:26:21 -0600 Subject: [PATCH] update dependency on requests to 2.6.0 Upgrade requests@2.3.0 to requests@2.6.0 to fix Session Fixation [Medium Severity][https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-40316] in requests@2.3.0 HTTP Request Redirection [Medium Severity][https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-40470] in requests@2.3.0 Information Exposure [High Severity][https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-72435] in requests@2.3.0 --- setup.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/setup.py b/setup.py index 72f5518..4db3207 100755 --- a/setup.py +++ b/setup.py @@ -45,7 +45,7 @@ "keyring==5.3", "oauth2client==1.5.2", "python-dateutil>=2.2", - "requests==2.3.0", + "requests==2.6.0", "sh==1.09", "six>=1.10.0", "xlrd==0.9.3",