From 1ad61b2dcfb572b9b99c5d3853b18f4d0df4e384 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 15 Aug 2024 05:17:13 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-7435780 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-7436273 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-7436514 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-7436646 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-7642790 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-7642791 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-7642813 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-7642814 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-5918878 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6043904 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6182918 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6219984 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6219986 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6514866 - https://snyk.io/vuln/SNYK-PYTHON-SQLPARSE-5426157 - https://snyk.io/vuln/SNYK-PYTHON-SQLPARSE-6615674 --- requirements.txt | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/requirements.txt b/requirements.txt index 0fbbd1b9..bcf989bb 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,12 +1,12 @@ asgiref==3.6.0 -Django==4.1.7 +Django==4.2.15 django-ckeditor==6.5.1 django-etc==1.4.0 django-hitcount==1.3.5 django-jazzmin==2.6.0 django-js-asset==2.0.0 django-modeltranslation==0.18.9 -Pillow==9.4.0 -sqlparse==0.4.3 +Pillow==10.3.0 +sqlparse==0.5.0 typing_extensions==4.5.0 whitenoise==6.4.0 \ No newline at end of file