From 1c19e781aa8d1af36c8827f7f1c13dbd35feedc4 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sat, 12 Nov 2022 00:07:13 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-1066259 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-1279042 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-1290072 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-1298665 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2312875 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2329158 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2329159 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2329160 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2389002 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2389021 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2606966 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2606969 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2940618 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2968205 - https://snyk.io/vuln/SNYK-PYTHON-REPORTLAB-1022145 - https://snyk.io/vuln/SNYK-PYTHON-REPORTLAB-473444 --- requirements.txt | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) mode change 100755 => 100644 requirements.txt diff --git a/requirements.txt b/requirements.txt old mode 100755 new mode 100644 index 2c62caa94..0511ab1e5 --- a/requirements.txt +++ b/requirements.txt @@ -1,4 +1,4 @@ -Django==1.11.29 +Django==3.2.15 django-extensions==1.9.8 git+https://github.com/dbca-wa/dpaw-utils.git@0.4.2#egg=dpaw-utils git+https://github.com/django-oscar/django-oscar.git@8a3288da439cc2a878f44ae5c5101043e658d2a2#egg=django-oscar @@ -7,7 +7,7 @@ git+https://github.com/scottp-dpaw/social-core.git@email_fix#egg=social-auth-cor webtemplate-dbca==0.6.0 coverage==4.3.1 coveralls==1.1 -reportlab==3.5.26 +reportlab==3.5.55 #django_bootstrap3==7.1.0 django_bootstrap3==12.0.3 django-braces>=1.8.1