From fe5ace4c71a3b95aeeb34c4925284e0bee38be3d Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 7 Jun 2024 08:00:42 +0000 Subject: [PATCH] fix: requirements/requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-CERTIFI-3164749 - https://snyk.io/vuln/SNYK-PYTHON-CERTIFI-5805047 - https://snyk.io/vuln/SNYK-PYTHON-GITPYTHON-2407255 - https://snyk.io/vuln/SNYK-PYTHON-GITPYTHON-3113858 - https://snyk.io/vuln/SNYK-PYTHON-GITPYTHON-5840584 - https://snyk.io/vuln/SNYK-PYTHON-GITPYTHON-5871282 - https://snyk.io/vuln/SNYK-PYTHON-GITPYTHON-5876644 - https://snyk.io/vuln/SNYK-PYTHON-GITPYTHON-6150683 - https://snyk.io/vuln/SNYK-PYTHON-IDNA-6597975 - https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-5595532 --- requirements/requirements.txt | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/requirements/requirements.txt b/requirements/requirements.txt index c4ae67fb0..c49344ade 100644 --- a/requirements/requirements.txt +++ b/requirements/requirements.txt @@ -10,3 +10,7 @@ transformers==4.5.0 tokenizers==0.10.2 lm_dataformat==0.0.19 ftfy==6.0.1 +certifi>=2023.7.22 # not directly required, pinned by Snyk to avoid a vulnerability +gitpython>=3.1.41 # not directly required, pinned by Snyk to avoid a vulnerability +idna>=3.7 # not directly required, pinned by Snyk to avoid a vulnerability +requests>=2.31.0 # not directly required, pinned by Snyk to avoid a vulnerability