From e8ee1f724ce7d21c4a6c121a9f488a8971bbe4f4 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 5 Oct 2023 00:13:15 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-5926907 --- requirements.txt | 1 + 1 file changed, 1 insertion(+) diff --git a/requirements.txt b/requirements.txt index 37a1d5c..b72c066 100644 --- a/requirements.txt +++ b/requirements.txt @@ -3,3 +3,4 @@ requests>=2.18.4,<=2.20.1 Werkzeug==0.15.5 pystache>=0.5.1,<=0.5.4 pycryptodome>=3.7.2, <4.0.0 +urllib3>=1.26.17 # not directly required, pinned by Snyk to avoid a vulnerability