From 8eaa98fa91be2c53bcabd8b277a103d853336ad3 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 21 Aug 2023 15:42:37 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-LXML-1047473 - https://snyk.io/vuln/SNYK-PYTHON-LXML-1047474 - https://snyk.io/vuln/SNYK-PYTHON-LXML-1088006 - https://snyk.io/vuln/SNYK-PYTHON-LXML-2316995 - https://snyk.io/vuln/SNYK-PYTHON-LXML-2940874 - https://snyk.io/vuln/SNYK-PYTHON-LXML-40279 - https://snyk.io/vuln/SNYK-PYTHON-LXML-72651 --- requirements.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index 0c649aa..51e664a 100644 --- a/requirements.txt +++ b/requirements.txt @@ -16,7 +16,7 @@ httplib2==0.8 iso8601==0.1.4 kombu==3.0.14 librabbitmq==1.0.3 -lxml==3.0.1 +lxml==4.9.1 psycopg2==2.4.5 pysaml2==0.4.2 python-memcached==1.48