From 4f2915555b2faa2c408945068baaa9dc1ec449b8 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 19 Jun 2025 05:01:40 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-PROTOBUF-10364902 --- requirements.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index 5b11b4c..1fca2e0 100644 --- a/requirements.txt +++ b/requirements.txt @@ -2,5 +2,5 @@ rook>=0.1.209 flask>=1.0,<=2.0 -e git+https://github.com/Rookout/python-flask.git@e56318f9c84978ecdaeaaff4aa819dc86f5509c7#egg=Flask_OpenTracing jaeger-client -protobuf>=3.18.3 # not directly required, pinned by Snyk to avoid a vulnerability +protobuf>=4.25.8 # not directly required, pinned by Snyk to avoid a vulnerability werkzeug==2.3.7