From 2408d7e03a6268a5113e8543f0904d2f2647d7aa Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 2 Feb 2024 04:14:49 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6210214 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6219984 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6219986 --- requirements.txt | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/requirements.txt b/requirements.txt index 727f363..20da1ac 100644 --- a/requirements.txt +++ b/requirements.txt @@ -14,10 +14,11 @@ WTForms==3.0.1 Werkzeug==2.2.3 requests==2.28.1 mysqlclient==2.1.1 -cryptography==41.0.0 +cryptography==42.0.2 alembic==1.9.1 itsdangerous==2.0.1 PyJWT==2.4.0 Jinja2==3.1.2 gevent==21.12.0 -setuptools>=65.5.1 # not directly required, pinned by Snyk to avoid a vulnerability \ No newline at end of file +setuptools>=65.5.1 # not directly required, pinned by Snyk to avoid a vulnerability +pillow>=10.2.0 # not directly required, pinned by Snyk to avoid a vulnerability \ No newline at end of file