From 9651db1cf6ecd329e69c0c931accfbf8b807e653 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 9 May 2025 14:01:05 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-10074036 - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-9964606 --- requirements.txt | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index 79861421..2627c4d6 100644 --- a/requirements.txt +++ b/requirements.txt @@ -10,7 +10,7 @@ chardet==3.0.4 dblpy==0.1.6 defusedxml==0.5.0 discord.py==1.3.4 -Django==2.1.2 +Django==4.2.21 django-bootstrap4==0.0.6 django-sslserver==0.20 docutils==0.14 @@ -44,3 +44,4 @@ urllib3==1.23 websockets==6.0 yarl==1.2.6 youtube-dl==2019.11.22 +setuptools>=78.1.1 # not directly required, pinned by Snyk to avoid a vulnerability