From 0b393e4e33d71086b04ca05cbb8ca343b8a1268d Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sun, 15 Sep 2024 23:05:18 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6091621 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6091622 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6209406 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6209407 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6645291 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6808823 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-7675597 - https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-6928867 - https://snyk.io/vuln/SNYK-PYTHON-ZIPP-7430899 --- requirements.txt | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index 3139a12f..6d3d902f 100644 --- a/requirements.txt +++ b/requirements.txt @@ -16,7 +16,7 @@ prometheus_client>=0.15.0 python-dateutil>=2.8.2 PyYAML>=6.0 py-zabbix>=1.1.7 -requests>=2.28.1 +requests>=2.32.2 sortedcontainers>=2.4.0 statsd-tags==3.2.1.post1 stomp.py>=8.1.0 @@ -24,3 +24,5 @@ tencentcloud-sdk-python>=3.0.795 texttable>=1.6.7 twilio>=7.16.0 tzlocal==2.1 +aiohttp>=3.10.2 # not directly required, pinned by Snyk to avoid a vulnerability +zipp>=3.19.1 # not directly required, pinned by Snyk to avoid a vulnerability