From 599ab1205d69c7b20a1f63915f067e3572508edf Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 8 Dec 2025 10:05:36 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-14157807 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-14157810 - https://snyk.io/vuln/SNYK-PYTHON-SQLPARSE-14157217 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-14192442 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-14192443 --- requirements.txt | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/requirements.txt b/requirements.txt index c0715a4c..b12669d0 100644 --- a/requirements.txt +++ b/requirements.txt @@ -4,7 +4,7 @@ beautifulsoup4==4.9.3 cached-property==1.5.2 certifi==2023.7.22 chardet==4.0.0 -Django==4.2.11 +Django==4.2.27 django-environ==0.4.5 django-extensions==3.1.1 django-livereload-server~=0.3 @@ -19,10 +19,10 @@ pytz==2023.3 requests==2.31.0 six==1.16.0 soupsieve~=2.2 -sqlparse==0.5.0 +sqlparse==0.5.4 stripe==5.4.0 tornado==6.3.3 -urllib3>=2.0.7 +urllib3>=2.6.0 celery==5.2.2 django-clacks>=0.1.0 cookiecutter==2.1.1 # not directly required, pinned by Snyk to avoid a vulnerability