From b0aef9744b7fce0941e9da59050dba48e1ed25b1 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 12 Jan 2022 16:17:31 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-1066259 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-1279042 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-1290072 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-1298665 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-173679 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2312875 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2329158 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2329159 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2329160 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-40778 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-40779 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-42054 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-42178 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-72888 - https://snyk.io/vuln/SNYK-PYTHON-DJANGORESTFRAMEWORK-1090569 - https://snyk.io/vuln/SNYK-PYTHON-DJANGORESTFRAMEWORK-450194 --- requirements.txt | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/requirements.txt b/requirements.txt index 000427c..ced1bda 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,8 +1,8 @@ -Django==2.0 +Django==2.2.26 coverage==4.4.2 django-nose==1.4.5 django-oauth-toolkit==1.0.0 -djangorestframework==3.7.3 +djangorestframework==3.11.2 factory-boy==2.9.2 git+https://github.com/Virako/django-rest-framework-social-oauth2 psycopg2==2.7.3.2