From ad56a31dc77bb4f2746d9d13b7de64130b572389 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 9 May 2025 14:00:24 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-CERTIFI-3164749 - https://snyk.io/vuln/SNYK-PYTHON-CERTIFI-5805047 - https://snyk.io/vuln/SNYK-PYTHON-PROTOBUF-3031740 - https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-6928867 - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-3180412 - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-7448482 - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-9964606 --- requirements.txt | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/requirements.txt b/requirements.txt index 60b5a1ba0..8fb0dbe7d 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,11 +1,11 @@ asn1crypto==0.24.0 -certifi==2018.8.24 +certifi==2023.7.22 cffi==1.11.5 colorama==0.3.7 pylint==2.3.1 jmespath==0.9.3 numpy==1.14.5 -protobuf==3.6.1 +protobuf==3.18.3 pyasn1==0.4.2 s3transfer==0.1.13 tensorflow==1.13.1 @@ -17,3 +17,5 @@ pytest==4.2.0 pytest-xdist==1.26.1 nose==1.3.7 pyyaml==5.1 +requests>=2.32.2 # not directly required, pinned by Snyk to avoid a vulnerability +setuptools>=78.1.1 # not directly required, pinned by Snyk to avoid a vulnerability