From 020e85055410a9563e8df6f658e3eff7ad952693 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 5 Jul 2024 07:07:51 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6592767 - https://snyk.io/vuln/SNYK-PYTHON-NLTK-5926697 - https://snyk.io/vuln/SNYK-PYTHON-NLTK-5926698 - https://snyk.io/vuln/SNYK-PYTHON-NUMPY-2321964 - https://snyk.io/vuln/SNYK-PYTHON-NUMPY-2321966 - https://snyk.io/vuln/SNYK-PYTHON-NUMPY-2321970 - https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-6928867 - https://snyk.io/vuln/SNYK-PYTHON-SCIKITLEARN-7217830 - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-3180412 --- requirements.txt | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/requirements.txt b/requirements.txt index fc99338..570bf67 100644 --- a/requirements.txt +++ b/requirements.txt @@ -20,7 +20,7 @@ chardet==3.0.4 Click==7.0 colour==0.1.5 constantly==15.1.0 -cryptography==42.0.4 +cryptography==42.0.6 cssselect==1.1.0 cycler==0.10.0 cymem==2.0.3 @@ -46,8 +46,8 @@ matplotlib==3.1.2 more-itertools==8.0.2 murmurhash==1.0.2 mysqlclient==1.4.6 -nltk==3.6.6 -numpy==1.22.0 +nltk==3.8.1 +numpy==1.22.2 orderedmultidict==1.0.1 parsel==1.5.2 passlib==1.7.3 @@ -74,7 +74,7 @@ python-dateutil==2.8.1 pytz==2019.3 PyYAML==5.4 queuelib==1.5.0 -requests==2.32.0 +requests==2.32.2 s3transfer==0.2.1 scandir==1.10.0 scikit-learn==1.5.0 @@ -98,3 +98,4 @@ w3lib==1.21.0 wasabi==0.4.2 yellowbrick==1.0.1 zope.interface==4.7.1 +setuptools>=65.5.1 # not directly required, pinned by Snyk to avoid a vulnerability