From 3384e638ef764e27195c38f1d1a968fd3afa4543 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 3 May 2024 17:51:35 +0000 Subject: [PATCH] fix: app/requirements-step-2.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6091621 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6091622 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6209406 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6209407 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6645291 - https://snyk.io/vuln/SNYK-PYTHON-FONTTOOLS-6133203 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-5918878 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6043904 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6182918 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6219984 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6219986 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6514866 --- app/requirements-step-2.txt | 3 +++ 1 file changed, 3 insertions(+) diff --git a/app/requirements-step-2.txt b/app/requirements-step-2.txt index 625ab94e..b4e1f982 100644 --- a/app/requirements-step-2.txt +++ b/app/requirements-step-2.txt @@ -17,3 +17,6 @@ newtulipy matplotlib>=3.0.1 scipy>=1.1.0 numpy>=1.22.2 # not directly required, pinned by Snyk to avoid a vulnerability +aiohttp>=3.9.4 # not directly required, pinned by Snyk to avoid a vulnerability +fonttools>=4.43.0 # not directly required, pinned by Snyk to avoid a vulnerability +pillow>=10.3.0 # not directly required, pinned by Snyk to avoid a vulnerability