From 9fc686111e959bf3278ad84451238672a8ec9471 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 3 Nov 2022 00:59:34 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2312875 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2329158 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2329159 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2329160 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2389002 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2389021 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2606966 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2606969 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2940618 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2968205 - https://snyk.io/vuln/SNYK-PYTHON-PYJWT-2840625 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-1533435 --- requirements.txt | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/requirements.txt b/requirements.txt index fa96ae1a..98eb2d2a 100644 --- a/requirements.txt +++ b/requirements.txt @@ -18,7 +18,7 @@ coreschema==0.0.4 coverage==5.3 cssselect==1.1.0 dj-database-url==0.5.0 -Django==3.1.13 +Django==3.2.15 django-cors-headers==3.3.0 django-environ==0.4.5 django-filter==2.4.0 @@ -64,7 +64,7 @@ pycryptodome==3.9.8 pydantic==1.6.2 pyee==7.0.4 Pygments==2.7.4 -PyJWT==1.7.1 +PyJWT==2.4.0 pyparsing==2.4.7 pyppeteer==0.0.25 pyquery==1.4.1 @@ -113,7 +113,7 @@ tqdm==4.49.0 typing==3.7.4.1 Unidecode==1.1.1 uritemplate==3.0.1 -urllib3==1.25.11 +urllib3==1.26.5 w3lib==1.22.0 webencodings==0.5.1 websockets==10.0