From 8fb9c8a88c027ed402b42db7a7c65266510a40d5 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sun, 13 Jul 2025 10:17:24 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-PROTOBUF-10364902 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-10390193 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-10390194 --- requirements.txt | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/requirements.txt b/requirements.txt index b9892bd..93d08e1 100644 --- a/requirements.txt +++ b/requirements.txt @@ -30,7 +30,7 @@ opentelemetry-sdk==1.16.0 opentelemetry-semantic-conventions==0.37b0 opentelemetry-util-http==0.37b0 packaging==23.1 -protobuf==4.24.3 +protobuf==4.25.8 pymongo==4.3.2 python-dateutil==2.8.2 python-lorem==1.1.2 @@ -38,7 +38,7 @@ requests==2.28.1 s3transfer==0.6.0 six==1.16.0 typing_extensions==4.8.0 -urllib3==1.26.12 +urllib3==2.5.0 Werkzeug==2.2.2 wrapt==1.15.0 zipp==3.9.0