From 4c1b680fd1411f5a224dc98dc229c3b2d848e431 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Tue, 16 Jan 2024 17:36:52 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-FLASK-5490129 - https://snyk.io/vuln/SNYK-PYTHON-JINJA2-1012994 - https://snyk.io/vuln/SNYK-PYTHON-JINJA2-6150717 - https://snyk.io/vuln/SNYK-PYTHON-PYLINT-1089548 - https://snyk.io/vuln/SNYK-PYTHON-PYLINT-609883 - https://snyk.io/vuln/SNYK-PYTHON-WERKZEUG-3319935 - https://snyk.io/vuln/SNYK-PYTHON-WERKZEUG-3319936 - https://snyk.io/vuln/SNYK-PYTHON-WERKZEUG-6035177 --- requirements.txt | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/requirements.txt b/requirements.txt index 3a65a6e..9a32c55 100644 --- a/requirements.txt +++ b/requirements.txt @@ -6,14 +6,14 @@ certifi==2020.6.20 chardet==3.0.4 click==7.1.2 coverage==5.3 -flask==1.1.2 +flask==2.2.5 flask-cors==3.0.9 flask-migrate==2.5.3 flask-sqlalchemy==2.4.4 idna==2.10 iniconfig==1.1.1 itsdangerous==1.1.0 -jinja2==2.11.2 +jinja2==3.1.3 jmespath==0.10.0 mako==1.1.3 markupsafe==1.1.1 @@ -38,7 +38,7 @@ six==1.15.0 sqlalchemy==1.3.20 toml==0.10.2 urllib3==1.25.11 -werkzeug==1.0.1 +werkzeug==2.3.8 appdirs==1.4.4 astroid==2.4.2 black==20.8b1 @@ -52,7 +52,7 @@ mccabe==0.6.1 mistune==0.8.4 mypy-extensions==0.4.3 pathspec==0.8.0 -pylint==2.6.0 +pylint==2.7.0 pylint-flask-sqlalchemy==0.2.0 pyrsistent==0.17.3 pyyaml==5.3.1