From d254c5b36c85d355276fefeda3e8a8b67145b2cd Mon Sep 17 00:00:00 2001 From: Ando David Roots <42958320+anroots-tw@users.noreply.github.com> Date: Wed, 24 Aug 2022 17:21:31 +0300 Subject: [PATCH] Pin exotel dep to 0.1.5 due to malicious release 0.1.6 Version 0.1.6 was malicious, loose constraint allows for an auto-update. Library seems unmaintained past 0.1.5 --- requirements.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index 9c32052d0..bd019e3a8 100644 --- a/requirements.txt +++ b/requirements.txt @@ -7,7 +7,7 @@ configparser>=3.5.0 croniter>=0.3.16 elasticsearch>=7.0.0 envparse>=0.2.0 -exotel>=0.1.3 +exotel==0.1.5 jira>=1.0.10,<1.0.15 jsonschema>=3.0.2 mock>=2.0.0