From 0215b4001e55a2011bc562e5eff09298d6b21991 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 8 Nov 2023 03:55:42 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-CERTIFI-3164749 - https://snyk.io/vuln/SNYK-PYTHON-CERTIFI-5805047 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-1727377 - https://snyk.io/vuln/SNYK-PYTHON-PYLINT-1089548 - https://snyk.io/vuln/SNYK-PYTHON-PYLINT-609883 - https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-5595532 - https://snyk.io/vuln/SNYK-PYTHON-RSA-1038401 - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-3180412 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-1085966 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-1533435 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-5926907 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-6002459 --- requirements.txt | 15 ++++++++------- 1 file changed, 8 insertions(+), 7 deletions(-) diff --git a/requirements.txt b/requirements.txt index f4fd586..4a90c20 100644 --- a/requirements.txt +++ b/requirements.txt @@ -3,7 +3,7 @@ attrs==20.3.0 autopep8==1.5.4 beautifulsoup4==4.9.3 cachetools==4.1.1 -certifi==2020.11.8 +certifi==2023.7.22 chardet==3.0.4 click==7.1.2 colorama==0.4.4 @@ -32,7 +32,7 @@ more-itertools==8.6.0 MouseInfo==0.1.3 numpy==1.19.5 oauthlib==3.1.0 -Pillow==8.0.1 +Pillow==8.3.2 pprintpp==0.4.0 protobuf==3.14.0 psutil==5.7.3 @@ -43,7 +43,7 @@ pycodestyle==2.6.0 pyflakes==2.2.0 PyGetWindow==0.0.9 pyjokes==0.6.0 -pylint==2.6.0 +pylint==2.7.0 PyMsgBox==1.0.9 pyperclip==1.8.1 pypiwin32==223 @@ -62,19 +62,20 @@ pywin32==300 qt5-applications==5.15.2.2.1 qt5-tools==5.15.2.1.0.1 ratelim==0.1.6 -requests==2.25.0 +requests==2.31.0 requests-oauthlib==1.3.0 -rsa==4.6 +rsa==4.7 selenium==3.141.0 six==1.15.0 soupsieve==2.0.1 SpeechRecognition==3.8.1 toml==0.10.2 uritemplate==3.0.1 -urllib3==1.26.2 +urllib3==1.26.18 wikipedia==1.4.0 wincertstore==0.2 wolframalpha==4.1.1 wrapt==1.12.1 xml-python==0.3.5 -xmltodict==0.12.0 \ No newline at end of file +xmltodict==0.12.0 +setuptools>=65.5.1 # not directly required, pinned by Snyk to avoid a vulnerability \ No newline at end of file