From b03c1fc478347b5507f7be0a348cffffca747540 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 10 Dec 2025 11:52:38 +0000 Subject: [PATCH] fix: backend/requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-PEEWEE-14157229 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-14192442 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-14192443 --- backend/requirements.txt | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/backend/requirements.txt b/backend/requirements.txt index ce55d2d347a..36213a3ac06 100644 --- a/backend/requirements.txt +++ b/backend/requirements.txt @@ -15,7 +15,7 @@ aiofiles sqlalchemy==2.0.38 alembic==1.14.0 -peewee==3.17.9 +peewee==3.18.3 peewee-migrate==1.12.2 psycopg2-binary==2.9.9 pgvector==0.4.0 @@ -138,3 +138,4 @@ opentelemetry-instrumentation-requests==0.53b1 opentelemetry-instrumentation-logging==0.53b1 opentelemetry-instrumentation-httpx==0.53b1 opentelemetry-instrumentation-aiohttp-client==0.53b1 +urllib3>=2.6.0 # not directly required, pinned by Snyk to avoid a vulnerability