From e7e31d09e7573dc73b50a6f860c6a93024f520c5 Mon Sep 17 00:00:00 2001 From: Terri Oda Date: Thu, 11 Apr 2024 08:51:44 -0700 Subject: [PATCH] chore: [Snyk] Security upgrade aiohttp from 3.8.6 to 3.9.2 (#4020) * fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6091621 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6091622 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6209406 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6209407 * fix: add [speedups] back in --------- Co-authored-by: snyk-bot --- requirements.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index c48ef39f99..2bb1210e05 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,4 +1,4 @@ -aiohttp[speedups]>=3.7.4 +aiohttp[speedups]>=3.9.2 beautifulsoup4 cvss defusedxml