From 94c66202ea77269e32d4737157d7f9203ce6b533 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 21 Feb 2022 21:21:40 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-GITPYTHON-2407255 - https://snyk.io/vuln/SNYK-PYTHON-PYYAML-590151 --- requirements.txt | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/requirements.txt b/requirements.txt index 4e0365f..0179f0f 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,7 +1,7 @@ -i https://pypi.org/simple aenum==2.2.3 gitdb==4.0.5 -gitpython==3.1.3 +gitpython==3.1.27 gremlinpython==3.4.6 isodate==0.6.0 marshmallow==3.6.0 @@ -9,7 +9,7 @@ mlspeclib==0.0.24 msgpack==1.0.0 pymysql==0.9.3 python-box==5.0.0a0 -pyyaml==5.3.1 +pyyaml==5.4 semver==2.10.1 six==1.15.0 smmap==3.0.4