From 9f321a106b655bc86ba15a46f999f1cf4f80254e Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sat, 3 Aug 2024 06:32:51 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-ANYIO-7361842 - https://snyk.io/vuln/SNYK-PYTHON-FASTAPI-6228055 - https://snyk.io/vuln/SNYK-PYTHON-JINJA2-6809379 - https://snyk.io/vuln/SNYK-PYTHON-NUMPY-2321964 - https://snyk.io/vuln/SNYK-PYTHON-NUMPY-2321966 - https://snyk.io/vuln/SNYK-PYTHON-NUMPY-2321970 - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-7448482 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-7267250 - https://snyk.io/vuln/SNYK-PYTHON-ZIPP-7430899 --- requirements.txt | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/requirements.txt b/requirements.txt index 04e3e28a5de..3eff867c798 100644 --- a/requirements.txt +++ b/requirements.txt @@ -15,7 +15,7 @@ arrow==1.3.0 cachetools==5.3.2 requests==2.31.0 -urllib3==2.0.7 +urllib3==2.2.2 jsonschema==4.19.1 @@ -23,7 +23,7 @@ TA-Lib==0.4.28 technical==1.4.2 tabulate==0.9.0 pycoingecko==3.1.0 -jinja2==3.1.3 +jinja2==3.1.4 tables==3.9.1 joblib==1.3.2 rich==13.7.0 @@ -41,7 +41,7 @@ orjson==3.9.10 sdnotify==0.3.2 # API Server -fastapi==0.103.2 +fastapi==0.109.1 pydantic==2.4.0 uvicorn==0.23.2 @@ -66,3 +66,6 @@ janus==1.0.0 ast-comments==1.2.1 packaging==23.2 +anyio>=4.4.0 # not directly required, pinned by Snyk to avoid a vulnerability +setuptools>=70.0.0 # not directly required, pinned by Snyk to avoid a vulnerability +zipp>=3.19.1 # not directly required, pinned by Snyk to avoid a vulnerability