From 9d878ae9b7c6bb1dd4f0c615ee266f7cb6443c3c Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sun, 30 Jun 2024 02:43:15 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-CERTIFI-3164749 - https://snyk.io/vuln/SNYK-PYTHON-CERTIFI-5805047 - https://snyk.io/vuln/SNYK-PYTHON-MAKO-3017600 - https://snyk.io/vuln/SNYK-PYTHON-PYGMENTS-1086606 - https://snyk.io/vuln/SNYK-PYTHON-PYGMENTS-1088505 - https://snyk.io/vuln/SNYK-PYTHON-PYGMENTS-5750273 --- requirements.txt | 3 +++ 1 file changed, 3 insertions(+) diff --git a/requirements.txt b/requirements.txt index e87080e..7adc17c 100644 --- a/requirements.txt +++ b/requirements.txt @@ -17,3 +17,6 @@ accessstatsapi==1.2.0 publicationstatsapi==1.2.0 articlemetaapi==1.14.19 altmetric==1.0.0 +certifi>=2023.7.22 # not directly required, pinned by Snyk to avoid a vulnerability +mako>=1.2.2 # not directly required, pinned by Snyk to avoid a vulnerability +pygments>=2.15.0 # not directly required, pinned by Snyk to avoid a vulnerability