Skip to content

Commit

Permalink
fix: backend_app/requirements.txt to reduce vulnerabilities
Browse files Browse the repository at this point in the history
The following vulnerabilities are fixed by pinning transitive dependencies:
- https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6808823
- https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6592767
  • Loading branch information
snyk-bot committed May 6, 2024
1 parent 4adcca1 commit 6afe820
Showing 1 changed file with 2 additions and 1 deletion.
3 changes: 2 additions & 1 deletion backend_app/requirements.txt
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
aiohttp==3.8.1
aiohttp==3.9.4
amqp==2.5.2
asgiref==3.3.4
async-timeout==4.0.1
Expand Down Expand Up @@ -74,3 +74,4 @@ botocore==1.19.25
django-cachalot==2.5.1
python-memcached==1.59
django-auth-adfs==1.9.5
cryptography>=42.0.6 # not directly required, pinned by Snyk to avoid a vulnerability

0 comments on commit 6afe820

Please sign in to comment.