From dd795f4726c0c06b9840a729a51a79c9a7cd5e5f Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Tue, 13 Aug 2024 02:31:47 +0000 Subject: [PATCH] fix: requirements.dev.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-AUTHLIB-7231109 - https://snyk.io/vuln/SNYK-PYTHON-BANDIT-6241859 - https://snyk.io/vuln/SNYK-PYTHON-BLACK-6256273 - https://snyk.io/vuln/SNYK-PYTHON-IPYTHON-3318382 - https://snyk.io/vuln/SNYK-PYTHON-NOTEBOOK-2441824 - https://snyk.io/vuln/SNYK-PYTHON-NOTEBOOK-2928995 - https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-6928867 - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-7448482 - https://snyk.io/vuln/SNYK-PYTHON-TORNADO-5537286 - https://snyk.io/vuln/SNYK-PYTHON-TORNADO-5840803 - https://snyk.io/vuln/SNYK-PYTHON-TORNADO-6041512 - https://snyk.io/vuln/SNYK-PYTHON-TORNADO-7217828 - https://snyk.io/vuln/SNYK-PYTHON-TORNADO-7217829 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-7267250 - https://snyk.io/vuln/SNYK-PYTHON-ZIPP-7430899 --- requirements.dev.txt | 13 ++++++++++--- 1 file changed, 10 insertions(+), 3 deletions(-) diff --git a/requirements.dev.txt b/requirements.dev.txt index 35e6f3b2..b788816b 100644 --- a/requirements.dev.txt +++ b/requirements.dev.txt @@ -1,6 +1,6 @@ -r ./requirements.txt -bandit==1.7.0 -black==22.3.0 +bandit==1.7.7 +black==24.3.0 codecov==2.1.11 coverage==6.0b1 darglint==1.7.0 @@ -10,7 +10,7 @@ interrogate==1.3.2 ipykernel==5.5.0 isort==5.6.4 mypy==0.790 -notebook==6.4.1 +notebook==6.4.12 papermill==2.3.1 pep8-naming==0.11.1 pre-commit==2.11.1 @@ -20,3 +20,10 @@ pytest-cov==2.10.1 pytest-order==1.0.0 pytest-xdist[psutil] safety +authlib>=1.3.1 # not directly required, pinned by Snyk to avoid a vulnerability +ipython>=8.10.0 # not directly required, pinned by Snyk to avoid a vulnerability +requests>=2.32.2 # not directly required, pinned by Snyk to avoid a vulnerability +setuptools>=70.0.0 # not directly required, pinned by Snyk to avoid a vulnerability +tornado>=6.4.1 # not directly required, pinned by Snyk to avoid a vulnerability +urllib3>=2.2.2 # not directly required, pinned by Snyk to avoid a vulnerability +zipp>=3.19.1 # not directly required, pinned by Snyk to avoid a vulnerability