From 15c38ab4dbe8012e2b2e70601af292a6344e0913 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 29 Sep 2022 09:14:09 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-GUNICORN-541164 - https://snyk.io/vuln/SNYK-PYTHON-JINJA2-1012994 - https://snyk.io/vuln/SNYK-PYTHON-JINJA2-174126 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-1014645 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-1533435 --- requirements.txt | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/requirements.txt b/requirements.txt index 79fe006..a7618bc 100644 --- a/requirements.txt +++ b/requirements.txt @@ -5,9 +5,9 @@ Flask==1.0 Flask-Limiter==0.9.3 flask-restplus==0.9.2 functools32==3.2.3.post2 -gunicorn==19.6.0 +gunicorn==19.10.0 itsdangerous==0.24 -Jinja2==2.9.4 +Jinja2==2.11.3 jsonschema==2.5.1 limits==1.2.1 MarkupSafe==0.23 @@ -19,3 +19,4 @@ pytz==2016.10 requests==2.20.0 six==1.10.0 Werkzeug==0.15.3 +urllib3>=1.26.5 # not directly required, pinned by Snyk to avoid a vulnerability