From b997d535706b2d6e010df45dc72cf0a3646b6975 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?St=C3=A9phane=20Brunner?= Date: Wed, 12 Jun 2024 10:52:19 +0200 Subject: [PATCH] Fix CVE [HIGH] cryptography@42.0.6: SNYK-PYTHON-CRYPTOGRAPHY-7161587 CWE-416 [Fixed in: 42.0.8]. [MEDIUM] requests@2.32.0: SNYK-PYTHON-REQUESTS-6928867 CWE-670 [Fixed in: 2.32.2]. --- ci/requirements.txt | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/ci/requirements.txt b/ci/requirements.txt index 85e2c8168c..2d3e16f68c 100644 --- a/ci/requirements.txt +++ b/ci/requirements.txt @@ -2,7 +2,7 @@ c2cciutils[checks,publish]==1.4.16 attrs>=22.2.0 # because c2cciutils 1.4.12 does not work with 19.3 setuptools>=65.5.1 # not directly required, pinned by Snyk to avoid a vulnerability certifi>=2022.12.7 # not directly required, pinned by Snyk to avoid a vulnerability -cryptography>=42.0.2 # not directly required, pinned by Snyk to avoid a vulnerability -requests>=2.31.0 # not directly required, pinned by Snyk to avoid a vulnerability +cryptography>=42.0.8 # not directly required, pinned by Snyk to avoid a vulnerability +requests>=2.32.2 # not directly required, pinned by Snyk to avoid a vulnerability urllib3>=1.26.17 # not directly required, pinned by Snyk to avoid a vulnerability idna>=3.7 # not directly required, pinned by Snyk to avoid a vulnerability