From 69b9193e28d1e3f0e77d3afeac33ca7d197267eb Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sun, 30 Oct 2022 23:16:19 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2312875 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2329158 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2329159 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2329160 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2389002 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2389021 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2606966 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2606969 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2940618 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2968205 - https://snyk.io/vuln/SNYK-PYTHON-LXML-2316995 - https://snyk.io/vuln/SNYK-PYTHON-LXML-2940874 - https://snyk.io/vuln/SNYK-PYTHON-PYJWT-2840625 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-1533435 --- requirements.txt | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/requirements.txt b/requirements.txt index fa96ae1a..8f16e8ad 100644 --- a/requirements.txt +++ b/requirements.txt @@ -18,7 +18,7 @@ coreschema==0.0.4 coverage==5.3 cssselect==1.1.0 dj-database-url==0.5.0 -Django==3.1.13 +Django==3.2.15 django-cors-headers==3.3.0 django-environ==0.4.5 django-filter==2.4.0 @@ -46,7 +46,7 @@ iniconfig==1.0.1 ipwhois==1.2.0 itypes==1.2.0 Jinja2==2.11.3 -lxml==4.6.3 +lxml==4.9.1 MarkupSafe==1.1.1 mixer==6.1.3 more-itertools==8.5.0 @@ -64,7 +64,7 @@ pycryptodome==3.9.8 pydantic==1.6.2 pyee==7.0.4 Pygments==2.7.4 -PyJWT==1.7.1 +PyJWT==2.4.0 pyparsing==2.4.7 pyppeteer==0.0.25 pyquery==1.4.1 @@ -113,7 +113,7 @@ tqdm==4.49.0 typing==3.7.4.1 Unidecode==1.1.1 uritemplate==3.0.1 -urllib3==1.25.11 +urllib3==1.26.5 w3lib==1.22.0 webencodings==0.5.1 websockets==10.0