From ed9eb2f5ef1548fcad11d0e0672bfff45cdc953f Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sun, 9 Oct 2022 06:06:00 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-1022152 - https://snyk.io/vuln/SNYK-PYTHON-PROTOBUF-3031740 --- requirements.txt | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/requirements.txt b/requirements.txt index 703d1f25..7e7e0757 100644 --- a/requirements.txt +++ b/requirements.txt @@ -12,7 +12,7 @@ google-api-python-client==1.8.3 google-auth<2.0dev,>=1.21.1 httplib2>=0.15.0 service_identity==17.0.0 -protobuf==3.15.8 +protobuf==3.18.3 pyopenssl==17.5.0 six==1.13.0 click==7.1.2 @@ -22,6 +22,6 @@ pyqrandomx>=0.3.0,<1.0.0 Flask>=1.0.0,<=1.1.2 json-rpc==1.10.8 idna==2.6 -cryptography==2.3 +cryptography==3.2 mock==2.0.0 daemonize==2.4.7