From 120ea6015e624b8a31a07ba3fadaa10154d2eb5b Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 20 Sep 2024 08:23:21 +0000 Subject: [PATCH] fix: requirements/requirements_dev.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-BLACK-6256273 - https://snyk.io/vuln/SNYK-PYTHON-FONTTOOLS-6133203 - https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-6928867 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-7267250 - https://snyk.io/vuln/SNYK-PYTHON-ZIPP-7430899 --- requirements/requirements_dev.txt | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/requirements/requirements_dev.txt b/requirements/requirements_dev.txt index 3618b315..e6610598 100644 --- a/requirements/requirements_dev.txt +++ b/requirements/requirements_dev.txt @@ -16,7 +16,7 @@ -r requirements_multiprocessing.txt -r requirements_pygame.txt bandit>=1.7.7 -black>=22.3.0 +black>=24.3.0 coveralls>=3.3.1 doc8>=0.11.2 #mccabe>=0.7.0 @@ -41,3 +41,7 @@ tox>=3.25.0 twine>=4.0.1 types-six>=1.1.1 wheel>=0.37.1 +fonttools>=4.43.0 # not directly required, pinned by Snyk to avoid a vulnerability +requests>=2.32.2 # not directly required, pinned by Snyk to avoid a vulnerability +urllib3>=2.2.2 # not directly required, pinned by Snyk to avoid a vulnerability +zipp>=3.19.1 # not directly required, pinned by Snyk to avoid a vulnerability