From 6a0c312cb4f64011c0ac049c67dace6364089c70 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sun, 1 Oct 2023 14:09:58 +0000 Subject: [PATCH 1/4] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-NUMPY-2321964 - https://snyk.io/vuln/SNYK-PYTHON-NUMPY-2321966 - https://snyk.io/vuln/SNYK-PYTHON-NUMPY-2321970 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-5918878 - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-3180412 --- requirements.txt | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/requirements.txt b/requirements.txt index 0d78461..1a47b07 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,4 +1,4 @@ -numpy>=1.12 +numpy>=1.22.2 notifiers matplotlib>=1.3.0 scipy>=0.18 @@ -19,4 +19,5 @@ pytest-pep8 pytest-xdist pytest-rerunfailures pytest-mpl -pillow>=6.2.3 # not directly required, pinned by Snyk to avoid a vulnerability +pillow>=10.0.1 # not directly required, pinned by Snyk to avoid a vulnerability +setuptools>=65.5.1 # not directly required, pinned by Snyk to avoid a vulnerability From a8f5aca1f998a3e75b1fb79fb5f2829a5a732476 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 1 Nov 2023 14:09:45 +0000 Subject: [PATCH 2/4] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-TORNADO-6041512 --- requirements.txt | 1 + 1 file changed, 1 insertion(+) diff --git a/requirements.txt b/requirements.txt index 0d78461..83a1b00 100644 --- a/requirements.txt +++ b/requirements.txt @@ -20,3 +20,4 @@ pytest-xdist pytest-rerunfailures pytest-mpl pillow>=6.2.3 # not directly required, pinned by Snyk to avoid a vulnerability +tornado>=6.3.3 # not directly required, pinned by Snyk to avoid a vulnerability From c3747687813cbc10705694b074b9fc4707091ec3 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 3 Nov 2023 14:27:26 +0000 Subject: [PATCH 3/4] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6043904 --- requirements.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index 0d78461..7c1a87b 100644 --- a/requirements.txt +++ b/requirements.txt @@ -19,4 +19,4 @@ pytest-pep8 pytest-xdist pytest-rerunfailures pytest-mpl -pillow>=6.2.3 # not directly required, pinned by Snyk to avoid a vulnerability +pillow>=10.0.0 # not directly required, pinned by Snyk to avoid a vulnerability From e7a6448d7b0cd76d38b850bb30db70905e452c4c Mon Sep 17 00:00:00 2001 From: Calum Chamberlain Date: Wed, 13 Dec 2023 09:07:20 +1300 Subject: [PATCH 4/4] Update requirements.txt --- requirements.txt | 1 + 1 file changed, 1 insertion(+) diff --git a/requirements.txt b/requirements.txt index 7c1a87b..caad608 100644 --- a/requirements.txt +++ b/requirements.txt @@ -19,4 +19,5 @@ pytest-pep8 pytest-xdist pytest-rerunfailures pytest-mpl +tornado>=6.3.3 # not directly required, pinned by Snyk to avoid a vulnerability pillow>=10.0.0 # not directly required, pinned by Snyk to avoid a vulnerability