From 545003c3049ecbc9463a8054fda61c2bcc2569cb Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 11 Jul 2024 08:44:17 +0000 Subject: [PATCH] fix: backend/requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-7435780 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-7436273 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-7436514 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-7436646 - https://snyk.io/vuln/SNYK-PYTHON-ZIPP-7430899 --- backend/requirements.txt | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/backend/requirements.txt b/backend/requirements.txt index c91b639..fd8d5b7 100644 --- a/backend/requirements.txt +++ b/backend/requirements.txt @@ -1,4 +1,4 @@ -Django>=1.8.6 +Django>=4.2.14 django-cors-headers>=0.13 djangorestframework>=3.3.1 django-oauth-toolkit>=0.9.0 @@ -7,3 +7,4 @@ djangorestframework-oauth>=1.0.1 gunicorn>=0.17.4 html2text>=2016.1.8 pytz>=2012f +zipp>=3.19.1 # not directly required, pinned by Snyk to avoid a vulnerability