From 96a506c5f64633768271473ea091127994692ab5 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Tue, 9 Jan 2024 18:46:22 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-NUMPY-2321964 - https://snyk.io/vuln/SNYK-PYTHON-NUMPY-2321966 - https://snyk.io/vuln/SNYK-PYTHON-NUMPY-2321969 - https://snyk.io/vuln/SNYK-PYTHON-NUMPY-2321970 - https://snyk.io/vuln/SNYK-PYTHON-NUMPY-42064 - https://snyk.io/vuln/SNYK-PYTHON-NUMPY-73513 - https://snyk.io/vuln/SNYK-PYTHON-WERKZEUG-3319935 - https://snyk.io/vuln/SNYK-PYTHON-WERKZEUG-3319936 --- requirements.txt | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index f6a22a0233..bcc8a20e27 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,4 +1,4 @@ -numpy==1.11.0 +numpy==1.22.2 networkx==1.11 -e git+https://github.com/keyphact/pgoapi.git@249d3be7fbbdabc7f9adea17cbc899d6549e47a2#egg=pgoapi geopy==1.11.0 @@ -22,3 +22,4 @@ mock==2.0.0 timeout-decorator==0.3.2 raven==5.23.0 demjson==2.2.4 +werkzeug>=2.2.3 # not directly required, pinned by Snyk to avoid a vulnerability