From c9f2b11ad2acc0e3b6067c0f54e856f48d45b4e9 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 23 Sep 2024 09:48:42 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-7267250 --- requirements.txt | 1 + 1 file changed, 1 insertion(+) diff --git a/requirements.txt b/requirements.txt index 80ff670d..7ea1a067 100644 --- a/requirements.txt +++ b/requirements.txt @@ -89,3 +89,4 @@ xmltodict==0.10.2 yamllint==1.15.0 #pyyaml>=5.4 # not directly required, pinned by Snyk to avoid a vulnerability. update: this breaks Python 3.5 build where this requirement is not found +urllib3>=2.2.2 # not directly required, pinned by Snyk to avoid a vulnerability