From 45c5a77a7a95cb715f1a497ce03be8120e047d52 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 6 May 2024 05:52:34 +0000 Subject: [PATCH] fix: virtualrequirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6057353 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6091621 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6091622 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6091623 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6209406 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6209407 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6645291 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6808823 - https://snyk.io/vuln/SNYK-PYTHON-IDNA-6597975 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-5926907 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-6002459 --- virtualrequirements.txt | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/virtualrequirements.txt b/virtualrequirements.txt index affa8c9..a32e7d6 100644 --- a/virtualrequirements.txt +++ b/virtualrequirements.txt @@ -1,6 +1,6 @@ # Dependencies for virtual enviroments # Testing in Arch Linux virtual enviroment Python 3.11.5 -aiohttp==3.8.5 +aiohttp==3.9.4 aiosignal==1.3.1 async-timeout==4.0.3 attrs==23.1.0 @@ -11,10 +11,10 @@ charset-normalizer==3.2.0 colorama==0.4.6 defusedxml==0.7.1 frozenlist==1.4.0 -idna==3.4 +idna==3.7 multidict==6.0.4 requests==2.31.0 soupsieve==2.5 tqdm==4.66.3 -urllib3==2.0.5 +urllib3==2.0.7 yarl==1.9.2