From 92e7c3f9f41c6474e59f6163484ac9d6fd64e610 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 28 Oct 2022 20:26:55 -0700 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-LXML-1047473 - https://snyk.io/vuln/SNYK-PYTHON-LXML-1047474 - https://snyk.io/vuln/SNYK-PYTHON-LXML-1088006 - https://snyk.io/vuln/SNYK-PYTHON-LXML-2316995 - https://snyk.io/vuln/SNYK-PYTHON-LXML-2940874 - https://snyk.io/vuln/SNYK-PYTHON-LXML-72651 - https://snyk.io/vuln/SNYK-PYTHON-PYJWT-2840625 --- requirements.txt | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index 146378c..9745608 100644 --- a/requirements.txt +++ b/requirements.txt @@ -2,5 +2,6 @@ twilio==6.35.3 inflection==0.3.1 yapf==0.16.2 jsbeautifier==1.6.14 -lxml==4.2.3 +lxml==4.9.1 inflection==0.3.1 +pyjwt>=2.4.0 # not directly required, pinned by Snyk to avoid a vulnerability