From c639938f7b915f177ff2961b15385ca751ed1cdf Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 18 Nov 2022 21:51:45 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-PROTOBUF-3031740 - https://snyk.io/vuln/SNYK-PYTHON-PROTOBUF-472377 - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-3113904 --- requirements.txt | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index f6a22a0233..98485ff883 100644 --- a/requirements.txt +++ b/requirements.txt @@ -2,7 +2,7 @@ numpy==1.11.0 networkx==1.11 -e git+https://github.com/keyphact/pgoapi.git@249d3be7fbbdabc7f9adea17cbc899d6549e47a2#egg=pgoapi geopy==1.11.0 -protobuf==3.0.0b4 +protobuf==3.18.3 requests==2.10.0 s2sphere==0.2.4 gpsoauth==0.3.0 @@ -22,3 +22,4 @@ mock==2.0.0 timeout-decorator==0.3.2 raven==5.23.0 demjson==2.2.4 +setuptools>=65.5.1 # not directly required, pinned by Snyk to avoid a vulnerability