From 95aa1991c1d3bfe253adbe6f629a548dd02d1853 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 5 Apr 2021 08:58:18 +0000 Subject: [PATCH 1/3] fix: {{cookiecutter.project_slug}}/requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-1090584 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-1090586 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-1090587 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-1090588 --- {{cookiecutter.project_slug}}/requirements.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/{{cookiecutter.project_slug}}/requirements.txt b/{{cookiecutter.project_slug}}/requirements.txt index 46527900..cdd93c2c 100644 --- a/{{cookiecutter.project_slug}}/requirements.txt +++ b/{{cookiecutter.project_slug}}/requirements.txt @@ -252,7 +252,7 @@ phonenumbers==8.12.19 # via -r {{cookiecutter.project_slug}}/requirements.in phonenumberslite==8.12.10 # via faker-e164 -pillow==8.1.1 +pillow==8.2.0 # via wagtail pip-api==0.0.14 # via isort From d3e153b7ef993ce6626b830f225fc034d3de8917 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 21 Apr 2021 08:58:18 +0000 Subject: [PATCH 2/3] fix: {{cookiecutter.project_slug}}/requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-WAGTAIL-1252240 --- {{cookiecutter.project_slug}}/requirements.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/{{cookiecutter.project_slug}}/requirements.txt b/{{cookiecutter.project_slug}}/requirements.txt index 46527900..a954c43e 100644 --- a/{{cookiecutter.project_slug}}/requirements.txt +++ b/{{cookiecutter.project_slug}}/requirements.txt @@ -426,7 +426,7 @@ virtualenv==20.0.31 # via pre-commit https://github.com/wagtail/wagtail-factories/archive/master.zip # via -r {{cookiecutter.project_slug}}/requirements.in -wagtail==2.12.3 +wagtail==2.12.4 # via # -r {{cookiecutter.project_slug}}/requirements.in # wagtail-factories From ffcdedf9df8f64419261b0412e8a904f1c961684 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 11 May 2021 12:49:53 +0000 Subject: [PATCH 3/3] build(deps): bump django-extensions from 3.1.1 to 3.1.3 Bumps [django-extensions](https://github.com/django-extensions/django-extensions) from 3.1.1 to 3.1.3. - [Release notes](https://github.com/django-extensions/django-extensions/releases) - [Changelog](https://github.com/django-extensions/django-extensions/blob/main/CHANGELOG.md) - [Commits](https://github.com/django-extensions/django-extensions/compare/3.1.1...3.1.3) Signed-off-by: dependabot[bot] --- {{cookiecutter.project_slug}}/requirements.txt | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/{{cookiecutter.project_slug}}/requirements.txt b/{{cookiecutter.project_slug}}/requirements.txt index 4e471281..79b5f611 100644 --- a/{{cookiecutter.project_slug}}/requirements.txt +++ b/{{cookiecutter.project_slug}}/requirements.txt @@ -101,7 +101,7 @@ django-el-pagination==3.3.0 # via -r {{cookiecutter.project_slug}}/requirements.in django-environ==0.4.5 # via -r {{cookiecutter.project_slug}}/requirements.in -django-extensions==3.1.1 +django-extensions==3.1.3 # via -r {{cookiecutter.project_slug}}/requirements.in django-filter==2.4.0 # via wagtail @@ -140,6 +140,7 @@ django==3.1.10 # django-colorful # django-debug-toolbar # django-el-pagination + # django-extensions # django-filter # django-intl-tel-input # django-leaflet