From 2735b028ac965597cd6e17b53dc12cbd0389ba99 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 14 Nov 2022 02:30:28 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-BOTO-2849305 - https://snyk.io/vuln/SNYK-PYTHON-BOTO-40479 - https://snyk.io/vuln/SNYK-PYTHON-JINJA2-1012994 - https://snyk.io/vuln/SNYK-PYTHON-JINJA2-174126 - https://snyk.io/vuln/SNYK-PYTHON-JINJA2-455616 - https://snyk.io/vuln/SNYK-PYTHON-PYGMENTS-1086606 - https://snyk.io/vuln/SNYK-PYTHON-PYGMENTS-1088505 - https://snyk.io/vuln/SNYK-PYTHON-PYRAMID-40730 - https://snyk.io/vuln/SNYK-PYTHON-PYRAMID-564353 - https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-72435 - https://snyk.io/vuln/SNYK-PYTHON-SPHINX-570772 - https://snyk.io/vuln/SNYK-PYTHON-SPHINX-570773 - https://snyk.io/vuln/SNYK-PYTHON-WEBOB-40490 --- requirements.txt | 13 +++++++------ 1 file changed, 7 insertions(+), 6 deletions(-) diff --git a/requirements.txt b/requirements.txt index ab879bf..6cf2207 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,13 +1,13 @@ -Jinja2==2.7.3 +Jinja2==2.11.3 LEPL==5.1.3 MarkupSafe==0.23 PasteDeploy==1.5.2 PyYAML==3.11 -Pygments==2.0.2 -WebOb==1.4.1 +Pygments==2.7.4 +WebOb==1.6.0a0 WebTest==2.0.18 beautifulsoup4==4.3.2 -boto==2.31.1 +boto==2.39.0 chaussette==1.2 cornice==1.0.0 coverage==3.7.1 @@ -22,13 +22,13 @@ pbkdf2==1.3 py==1.4.26 pycrypto==2.6.1 pyramid-exclog==0.7 -pyramid==1.5.7 +pyramid==1.6a2 pytest==2.6.4 python-coveralls==2.5.0 pytz==2014.10 repoze.lru==0.6 redis==2.10.5 -requests==2.7.0 +requests==2.20 setuptools==7.0 sh==1.11 simplejson==3.6.5 @@ -44,3 +44,4 @@ requests_mock==1.3.0 git+https://github.com/openprocurement/barbecue.git git+https://github.com/openprocurement/python-json-patch.git git+https://github.com/openprocurement/rfc6266.git +sphinx>=3.0.4 # not directly required, pinned by Snyk to avoid a vulnerability