From 31fc3a3849c3994ea207a532c843bb0311c097d9 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 8 Mar 2024 15:16:13 +0000 Subject: [PATCH] fix: requirements.dev.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-BANDIT-6241859 - https://snyk.io/vuln/SNYK-PYTHON-IPYTHON-3318382 - https://snyk.io/vuln/SNYK-PYTHON-NOTEBOOK-2441824 - https://snyk.io/vuln/SNYK-PYTHON-NOTEBOOK-2928995 - https://snyk.io/vuln/SNYK-PYTHON-TORNADO-5537286 - https://snyk.io/vuln/SNYK-PYTHON-TORNADO-5840803 - https://snyk.io/vuln/SNYK-PYTHON-TORNADO-6041512 --- requirements.dev.txt | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/requirements.dev.txt b/requirements.dev.txt index 35e6f3b2..cb4ce32f 100644 --- a/requirements.dev.txt +++ b/requirements.dev.txt @@ -1,5 +1,5 @@ -r ./requirements.txt -bandit==1.7.0 +bandit==1.7.7 black==22.3.0 codecov==2.1.11 coverage==6.0b1 @@ -10,7 +10,7 @@ interrogate==1.3.2 ipykernel==5.5.0 isort==5.6.4 mypy==0.790 -notebook==6.4.1 +notebook==6.4.12 papermill==2.3.1 pep8-naming==0.11.1 pre-commit==2.11.1 @@ -20,3 +20,5 @@ pytest-cov==2.10.1 pytest-order==1.0.0 pytest-xdist[psutil] safety +ipython>=8.10.0 # not directly required, pinned by Snyk to avoid a vulnerability +tornado>=6.3.3 # not directly required, pinned by Snyk to avoid a vulnerability