From bf67252f48100b1bbea7830f832841b51d7782be Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Tue, 24 May 2022 19:58:13 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2329158 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2329159 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2329160 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2389002 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2389021 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2606966 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2606969 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-2329135 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-2331901 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-2331905 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-2331907 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-2397241 - https://snyk.io/vuln/SNYK-PYTHON-WAGTAIL-2342656 --- requirements.txt | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index e7f7b76c..045d10ff 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,4 +1,4 @@ -wagtail==2.12.5 +wagtail==2.15.2 boto==2.49.0 celery==4.4.2 django_compressor==2.4 @@ -29,3 +29,5 @@ gunicorn==20.0.4 # Tests django-nose==1.4.6 factory_boy==2.12.0 +django>=3.2.13 # not directly required, pinned by Snyk to avoid a vulnerability +pillow>=9.0.1 # not directly required, pinned by Snyk to avoid a vulnerability