From 0cc0e3cffd1e137bbe85fd6caf1776dec4000138 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 2 Apr 2026 03:04:42 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-15809188 - https://snyk.io/vuln/SNYK-PYTHON-PYGMENTS-15746419 - https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-15763443 --- requirements.txt | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/requirements.txt b/requirements.txt index e75ad04d..cd9303b2 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,8 +1,8 @@ -requests~=2.32.0 +requests~=2.33.0 # Core dependencies django>=4.2.0,<5.0.0 python-dotenv>=1.0.0 -cryptography>=43.0.1,<47.0 +cryptography>=46.0.6 pyjwt>=2.10.0 fastapi>=0.110.0 flask>=3.0.0 @@ -35,3 +35,4 @@ twine>=4.0.2 # Other dependencies httpx>=0.25.0,<0.29.0 +pygments>=2.20.0 # not directly required, pinned by Snyk to avoid a vulnerability