From f6f9530376cac4a732fba9875a8c77c7be87b75c Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Tue, 15 Nov 2022 21:08:32 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-PROTOBUF-3031740 - https://snyk.io/vuln/SNYK-PYTHON-PROTOBUF-472377 - https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-72435 - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-3113904 --- requirements.txt | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/requirements.txt b/requirements.txt index f6a22a0233..e0f44b3664 100644 --- a/requirements.txt +++ b/requirements.txt @@ -2,8 +2,8 @@ numpy==1.11.0 networkx==1.11 -e git+https://github.com/keyphact/pgoapi.git@249d3be7fbbdabc7f9adea17cbc899d6549e47a2#egg=pgoapi geopy==1.11.0 -protobuf==3.0.0b4 -requests==2.10.0 +protobuf==3.18.3 +requests==2.20 s2sphere==0.2.4 gpsoauth==0.3.0 protobuf-to-dict==0.1.0 @@ -22,3 +22,4 @@ mock==2.0.0 timeout-decorator==0.3.2 raven==5.23.0 demjson==2.2.4 +setuptools>=65.5.1 # not directly required, pinned by Snyk to avoid a vulnerability