From cf7c94db07381c69cda3ff97c465dbdcf24e5e38 Mon Sep 17 00:00:00 2001 From: Robert Burns Date: Thu, 8 Aug 2024 04:42:08 -0400 Subject: [PATCH] Update dependencies for vulnerabilities (#1472) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Upgrade jinja2@3.1.2 to jinja2@3.1.4 to fix ✗ Cross-site Scripting (XSS) [Medium Severity][https://security.snyk.io/vuln/SNYK-PYTHON-JINJA2-6150717] in jinja2@3.1.2 introduced by jinja2@3.1.2 and 3 other path(s) ✗ Cross-site Scripting (XSS) [Medium Severity][https://security.snyk.io/vuln/SNYK-PYTHON-JINJA2-6809379] in jinja2@3.1.2 introduced by jinja2@3.1.2 and 3 other path(s) Upgrade requests@2.31.0 to requests@2.32.2 to fix ✗ Always-Incorrect Control Flow Implementation [Medium Severity][https://security.snyk.io/vuln/SNYK-PYTHON-REQUESTS-6928867] in requests@2.31.0 introduced by requests@2.31.0 Upgrade urllib3@2.0.7 to urllib3@2.2.2 to fix ✗ Improper Removal of Sensitive Information Before Storage or Transfer [Medium Severity][https://security.snyk.io/vuln/SNYK-PYTHON-URLLIB3-7267250] in urllib3@2.0.7 introduced by urllib3@2.0.7 and 1 other path(s) --- requirements.txt | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/requirements.txt b/requirements.txt index 603c093b27..0b15e359e7 100644 --- a/requirements.txt +++ b/requirements.txt @@ -6,7 +6,7 @@ colorama==0.4.6 feedgen==0.9.0 ghp-import==2.1.0 idna==3.7 -Jinja2==3.1.2 +Jinja2==3.1.4 lxml==4.9.3 Markdown==3.4.4 MarkupSafe==2.1.3 @@ -24,7 +24,7 @@ python-dateutil==2.8.2 PyYAML==6.0.1 pyyaml_env_tag==0.1 regex==2022.10.31 -requests==2.31.0 +requests==2.32.2 six==1.16.0 -urllib3==2.0.7 +urllib3==2.2.2 watchdog==3.0.0