From e77eb80a4302a5e33c6b6c81662dc45b6a5db360 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 17 Nov 2022 10:04:54 +0000 Subject: [PATCH] fix: pip-sample/requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-PROTOBUF-3031740 - https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-72435 - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-3113904 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-1014645 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-1533435 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-174323 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-174464 --- pip-sample/requirements.txt | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/pip-sample/requirements.txt b/pip-sample/requirements.txt index 680d08166..cf4d49bbd 100644 --- a/pip-sample/requirements.txt +++ b/pip-sample/requirements.txt @@ -38,7 +38,7 @@ parso==0.3.1 pexpect==4.6.0 pickleshare==0.7.5 prometheus-client==0.3.1 -protobuf==3.6.1 +protobuf==3.18.3 protobuf-to-dict==0.1.0 ptyprocess==0.6.0 Pygments==2.2.0 @@ -48,7 +48,7 @@ python-dateutil==2.7.3 pytz==2018.5 pyzmq==17.1.2 qtconsole==4.4.1 -requests==2.19.1 +requests==2.20 requests-oauthlib==1.0.0 Send2Trash==1.5.0 simplegeneric==0.8.1 @@ -58,10 +58,11 @@ testpath==0.4.1 tornado==5.1.1 traitlets==4.3.2 tweepy==3.6.0 -urllib3==1.23 +urllib3==1.26.5 virtualenv==16.0.0 wcwidth==0.1.7 webencodings==0.5.1 Werkzeug==0.14.1 widgetsnbextension==3.4.2 xlrd==1.1.0 +setuptools>=65.5.1 # not directly required, pinned by Snyk to avoid a vulnerability