From a7b4ad1af939876fb3be6bd0798b2ed9448c990d Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 17 Oct 2024 03:26:27 +0000 Subject: [PATCH] fix: requirements-dev.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-6928867 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-7267250 - https://snyk.io/vuln/SNYK-PYTHON-ZIPP-7430899 --- requirements-dev.txt | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/requirements-dev.txt b/requirements-dev.txt index 2007d85..f5d57ec 100644 --- a/requirements-dev.txt +++ b/requirements-dev.txt @@ -6,4 +6,7 @@ flake8==3.9.2 dataclasses scanoss importlib-metadata==4.12.0 -pytest-xdist \ No newline at end of file +pytest-xdist +requests>=2.32.2 # not directly required, pinned by Snyk to avoid a vulnerability +urllib3>=2.2.2 # not directly required, pinned by Snyk to avoid a vulnerability +zipp>=3.19.1 # not directly required, pinned by Snyk to avoid a vulnerability \ No newline at end of file