From 33d66751227f126f9782561a94546e5ae8964b4d Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 5 Oct 2022 20:51:23 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-GITPYTHON-2407255 - https://snyk.io/vuln/SNYK-PYTHON-PYYAML-590151 --- requirements.txt | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/requirements.txt b/requirements.txt index ac387bc..c34c42d 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,7 +1,7 @@ -i https://pypi.org/simple aenum==2.2.3 gitdb==4.0.5 -gitpython==3.1.3 +gitpython==3.1.27 gremlinpython==3.4.7 isodate==0.6.0 marshmallow==3.6.1 @@ -9,7 +9,7 @@ mlspeclib==0.0.25 msgpack==1.0.0 pymysql==0.9.3 python-box==5.0.0a0 -pyyaml==5.3.1 +pyyaml==5.4 semver==2.10.1 six==1.15.0 smmap==3.0.4