From b4aca881edfd0f949d75ffabcb6dac2815951ee3 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 14 Jan 2026 08:49:32 +0000 Subject: [PATCH] fix: backend/requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-FILELOCK-14912448 - https://snyk.io/vuln/SNYK-PYTHON-PYPDF-14912439 - https://snyk.io/vuln/SNYK-PYTHON-PYPDF-14912440 - https://snyk.io/vuln/SNYK-PYTHON-TORCH-13052805 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-14896210 --- backend/requirements.txt | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/backend/requirements.txt b/backend/requirements.txt index ce55d2d347a..f16147d8571 100644 --- a/backend/requirements.txt +++ b/backend/requirements.txt @@ -60,7 +60,7 @@ einops==0.8.1 ftfy==6.2.3 -pypdf==4.3.1 +pypdf==6.6.0 fpdf2==2.8.2 pymdown-extensions==10.14.2 docx2txt==0.8 @@ -138,3 +138,6 @@ opentelemetry-instrumentation-requests==0.53b1 opentelemetry-instrumentation-logging==0.53b1 opentelemetry-instrumentation-httpx==0.53b1 opentelemetry-instrumentation-aiohttp-client==0.53b1 +filelock>=3.20.3 # not directly required, pinned by Snyk to avoid a vulnerability +torch>=2.9.0 # not directly required, pinned by Snyk to avoid a vulnerability +urllib3>=2.6.3 # not directly required, pinned by Snyk to avoid a vulnerability