From 421dfcba7bd0d62a61117a457ef0914a648ceb3a Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 2 Apr 2026 06:11:24 +0000 Subject: [PATCH] fix: requirements_versions.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-FONTTOOLS-15869939 - https://snyk.io/vuln/SNYK-PYTHON-TRANSFORMERS-15166618 --- requirements_versions.txt | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/requirements_versions.txt b/requirements_versions.txt index e84bd4270a8..bea01d3f6ae 100644 --- a/requirements_versions.txt +++ b/requirements_versions.txt @@ -28,5 +28,6 @@ tomesd==0.1.3 torch torchdiffeq==0.2.3 torchsde==0.2.5 -transformers==4.30.2 +transformers==5.0.0rc3 httpx==0.24.1 +fonttools>=4.62.0 # not directly required, pinned by Snyk to avoid a vulnerability