From 71659cec729658dd35f9aea10a9116a3ef722ae2 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 12 Jan 2026 07:42:43 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871873 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871876 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871877 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871888 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871929 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871954 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871979 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14872000 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-14896210 --- requirements.txt | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index 8685fd00465..f0af7e9693c 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,6 +1,6 @@ aiofiles==0.6.0 aiogithubapi>=2.0.0<3.0.0 -aiohttp>=3.6.2,<4.0 +aiohttp>=3.13.3 aresponses==2.0.0 asynctest==0.13.0 attrs==20.3.0 @@ -18,3 +18,4 @@ pytest-socket==0.3.5 queueman==0.5 requests==2.25.0 semantic_version==2.8.5 +urllib3>=2.6.3 # not directly required, pinned by Snyk to avoid a vulnerability