From b8e2718d5d1b02ec9f871f8ebbb52bf0b46d28d1 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sat, 23 Mar 2024 17:56:38 +0000 Subject: [PATCH] fix: requirements/base.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6091621 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6091622 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6209406 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-6209407 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-5918878 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6043904 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6182918 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6219984 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6219986 --- requirements/base.txt | 1 + 1 file changed, 1 insertion(+) diff --git a/requirements/base.txt b/requirements/base.txt index a09bde86..35aa291d 100644 --- a/requirements/base.txt +++ b/requirements/base.txt @@ -144,3 +144,4 @@ pymisp==2.4.184.2 # https://github.com/python-ldap/python-ldap python-ldap==3.4.4 django-auth-ldap==4.6.0 +aiohttp>=3.9.2 # not directly required, pinned by Snyk to avoid a vulnerability