From f4bda58592f0eec28e366ffb683b804df69e5a03 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sat, 2 Dec 2023 01:57:50 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-CERTIFI-3164749 - https://snyk.io/vuln/SNYK-PYTHON-CERTIFI-5805047 - https://snyk.io/vuln/SNYK-PYTHON-NUMPY-2321969 - https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-5595532 - https://snyk.io/vuln/SNYK-PYTHON-UJSON-2359034 - https://snyk.io/vuln/SNYK-PYTHON-UJSON-2940619 - https://snyk.io/vuln/SNYK-PYTHON-UJSON-2942122 --- requirements.txt | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/requirements.txt b/requirements.txt index 2c939d49..fffc5e9f 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,13 +1,14 @@ cython>=0.24,<0.28.0 -numpy>=1.7 +numpy>=1.21.0rc1 cymem>=1.30,<1.32 preshed>=1.0.0,<2.0.0 thinc>=6.10.3,<6.11.0 murmurhash>=0.28,<0.29 plac<1.0.0,>=0.9.6 -ujson>=1.35 +ujson>=5.4.0 dill>=0.2,<0.3 regex==2017.4.5 -requests>=2.13.0,<3.0.0 +requests>=2.31.0,<3.0.0 mock>=2.0.0,<3.0.0 pathlib==1.0.1; python_version < "3.4" +certifi>=2023.7.22 # not directly required, pinned by Snyk to avoid a vulnerability