From e4d3693b6cceb52946c18453bbe52c55f2e774f5 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sat, 13 Jul 2024 08:58:02 +0000 Subject: [PATCH] fix: requirements/prod.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-FLASK-5490129 - https://snyk.io/vuln/SNYK-PYTHON-WERKZEUG-6035177 - https://snyk.io/vuln/SNYK-PYTHON-WERKZEUG-6808933 - https://snyk.io/vuln/SNYK-PYTHON-ZIPP-7430899 --- requirements/prod.txt | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) mode change 100755 => 100644 requirements/prod.txt diff --git a/requirements/prod.txt b/requirements/prod.txt old mode 100755 new mode 100644 index 5567a3301..fa60aafe5 --- a/requirements/prod.txt +++ b/requirements/prod.txt @@ -1,4 +1,4 @@ -Flask==2.0.2 +Flask==2.2.5 Flask-Bootstrap==3.3.7.1 Flask-Login==0.5.0 Flask-Migrate==3.1.0 @@ -8,3 +8,5 @@ Flask-WTF==0.15.1 email_validator==1.1.3 python-dotenv==0.19.1 prometheus-flask-exporter==0.18.5 +werkzeug>=3.0.3 # not directly required, pinned by Snyk to avoid a vulnerability +zipp>=3.19.1 # not directly required, pinned by Snyk to avoid a vulnerability