From c25c8590aa4ceb5c7638eae8063131b27e90d19a Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 9 May 2024 20:32:43 +0000 Subject: [PATCH] fix: tools/release/dependencies/requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-CERTIFI-3164749 - https://snyk.io/vuln/SNYK-PYTHON-CERTIFI-5805047 - https://snyk.io/vuln/SNYK-PYTHON-IDNA-6597975 - https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-5595532 - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-3180412 --- tools/release/dependencies/requirements.txt | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/tools/release/dependencies/requirements.txt b/tools/release/dependencies/requirements.txt index d7c3ce6..30057f4 100644 --- a/tools/release/dependencies/requirements.txt +++ b/tools/release/dependencies/requirements.txt @@ -3,3 +3,7 @@ click jira pyyaml dogpile.cache +certifi>=2023.7.22 # not directly required, pinned by Snyk to avoid a vulnerability +idna>=3.7 # not directly required, pinned by Snyk to avoid a vulnerability +requests>=2.31.0 # not directly required, pinned by Snyk to avoid a vulnerability +setuptools>=65.5.1 # not directly required, pinned by Snyk to avoid a vulnerability