From 6cbaf37e2f96493d3a0e109dd5b5899dcf9059bd Mon Sep 17 00:00:00 2001 From: Kody Stribrny Date: Wed, 25 Oct 2023 15:42:33 -0700 Subject: [PATCH] Update link verifier to use Python 3.7 and urllib3 v2 This is done to resolve two dependabot alerts. https://github.com/aws/aws-iot-device-sdk-embedded-C/security/dependabot/9 https://github.com/aws/aws-iot-device-sdk-embedded-C/security/dependabot/8 --- link-verifier/action.yml | 2 ++ link-verifier/requirements.txt | 2 +- 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/link-verifier/action.yml b/link-verifier/action.yml index 8136da6f..ee911861 100644 --- a/link-verifier/action.yml +++ b/link-verifier/action.yml @@ -29,6 +29,8 @@ runs: steps: - name: Setup Python for link verifier action uses: actions/setup-python@v3 + with: + python-version: '3.7' # Minimum version for urllib v2 (https://urllib3.readthedocs.io/en/latest/v2-migration-guide.html) - env: # The bash escape character is \033 diff --git a/link-verifier/requirements.txt b/link-verifier/requirements.txt index 1e2102c2..326141fe 100644 --- a/link-verifier/requirements.txt +++ b/link-verifier/requirements.txt @@ -6,4 +6,4 @@ idna==2.10 requests==2.31.0 soupsieve==2.1 termcolor==1.1.0 -urllib3 +urllib3>=2.0.7