From fae550656256538ad87b14fd9f0c3f0e85f60338 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 21 Oct 2022 15:38:27 +0000 Subject: [PATCH] fix: dev_requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-PYYAML-42159 - https://snyk.io/vuln/SNYK-PYTHON-PYYAML-559098 - https://snyk.io/vuln/SNYK-PYTHON-PYYAML-590151 --- dev_requirements.txt | 1 + 1 file changed, 1 insertion(+) diff --git a/dev_requirements.txt b/dev_requirements.txt index a6a5a39..8cd1844 100644 --- a/dev_requirements.txt +++ b/dev_requirements.txt @@ -13,3 +13,4 @@ flaky>=3.5.3,<4 # Test requirements pytest-dbt-adapter==0.4.0 +pyyaml>=5.4 # not directly required, pinned by Snyk to avoid a vulnerability