From 8cb42d24685fd40dd05b90a7eb64c82bc2622e94 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sun, 30 Oct 2022 19:45:18 -0700 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-LXML-1047473 - https://snyk.io/vuln/SNYK-PYTHON-LXML-1047474 - https://snyk.io/vuln/SNYK-PYTHON-LXML-1088006 - https://snyk.io/vuln/SNYK-PYTHON-LXML-2316995 - https://snyk.io/vuln/SNYK-PYTHON-LXML-2940874 - https://snyk.io/vuln/SNYK-PYTHON-LXML-72651 - https://snyk.io/vuln/SNYK-PYTHON-MAKO-3017600 - https://snyk.io/vuln/SNYK-PYTHON-PYJWT-2840625 - https://snyk.io/vuln/SNYK-PYTHON-SQLALCHEMY-173678 --- requirements.txt | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/requirements.txt b/requirements.txt index c1b286d..369f585 100644 --- a/requirements.txt +++ b/requirements.txt @@ -12,7 +12,7 @@ Flask-Session==0.3.1 # External libraries -SQLAlchemy==1.0.11 +SQLAlchemy==1.2.18 twilio==6.9.0 passlib==1.6.5 bcrypt==2.0.0 @@ -24,5 +24,7 @@ pysocks==1.6.6 unittest2==1.1.0 coverage==4.0.3 xmlunittest==0.3.2 -lxml==3.4 +lxml==4.9.1 mock==2.0.0 +mako>=1.2.2 # not directly required, pinned by Snyk to avoid a vulnerability +pyjwt>=2.4.0 # not directly required, pinned by Snyk to avoid a vulnerability