From d19e608a61fda596cd3bcdc5391f7e4a1a0640b6 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sun, 13 Nov 2022 07:02:05 +0000 Subject: [PATCH] fix: requirements/dev.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-HTTPIE-2419118 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-1014645 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-1533435 --- requirements/dev.txt | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/requirements/dev.txt b/requirements/dev.txt index ceac7af5..1c2d6bc1 100644 --- a/requirements/dev.txt +++ b/requirements/dev.txt @@ -3,7 +3,8 @@ ForgeryPy==0.1 Pygments==2.7.4 colorama==0.3.9 coverage==4.4.1 -httpie==1.0.3 +httpie==3.1.0 requests==2.20.0 selenium==3.5.0 unittest-xml-reporting==2.1.0 +urllib3>=1.26.5 # not directly required, pinned by Snyk to avoid a vulnerability