From 5fdcd7b6df82dd111bf7e134d64f8bb1cebb389f Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 21 Mar 2024 18:25:18 +0000 Subject: [PATCH] fix: requirements-dev.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-BLACK-6256273 - https://snyk.io/vuln/SNYK-PYTHON-CERTIFI-3164749 - https://snyk.io/vuln/SNYK-PYTHON-CERTIFI-5805047 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3112177 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3112180 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3172287 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3314966 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3315324 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3315328 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3315331 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3315452 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3315972 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3315975 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3316038 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3316211 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-5663682 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-5777683 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-5813745 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-5813746 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-5813750 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-5914629 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6036192 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6050294 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6092044 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6126975 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6149518 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6157248 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6210214 - https://snyk.io/vuln/SNYK-PYTHON-JUPYTERCORE-3063766 - https://snyk.io/vuln/SNYK-PYTHON-PYGMENTS-5750273 - https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-5595532 - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-3180412 - https://snyk.io/vuln/SNYK-PYTHON-TORNADO-5537286 - https://snyk.io/vuln/SNYK-PYTHON-TORNADO-5840803 - https://snyk.io/vuln/SNYK-PYTHON-TORNADO-6041512 --- requirements-dev.txt | 15 ++++++++------- 1 file changed, 8 insertions(+), 7 deletions(-) diff --git a/requirements-dev.txt b/requirements-dev.txt index 03c110e7..cf3f1aeb 100644 --- a/requirements-dev.txt +++ b/requirements-dev.txt @@ -7,13 +7,13 @@ asttokens==2.0.5 attrs==21.4.0 backcall==0.2.0 backports.entry-points-selectable==1.1.1 -black==21.12b0 +black==24.3.0 bleach==5.0.1 blessed==1.19.1 boto3==1.24.25 botocore==1.27.25 bullet==2.2.0 -certifi==2022.6.15 +certifi==2023.7.22 cffi==1.15.1 chardet==4.0.0 charset-normalizer==2.0.12 @@ -25,7 +25,7 @@ colorama==0.4.5 colorclass==2.2.2 commonmark==0.9.1 coverage==6.4.1 -cryptography==37.0.4 +cryptography==42.0.2 dacite==1.6.0 dataclass-csv==1.4.0 DataProperty==0.55.0 @@ -65,7 +65,7 @@ jedi==0.18.1 jeepney==0.8.0 jmespath==1.0.1 jupyter-client==7.3.4 -jupyter-core==4.11.0 +jupyter-core==4.11.2 keyring==23.6.0 log-symbols==0.0.14 lxml==4.9.1 @@ -100,7 +100,7 @@ pycparser==2.21 pydocstyle==6.1.1 pyfiglet==0.8.post1 pyflakes==2.4.0 -Pygments==2.12.0 +Pygments==2.15.0 pyparsing==3.0.9 pytest==7.1.2 pytest-black==0.3.12 @@ -119,7 +119,7 @@ pyzmq==23.2.0 rapidfuzz==2.1.2 readme-renderer==35.0 regex==2022.6.2 -requests==2.28.1 +requests==2.31.0 requests-toolbelt==0.9.1 rfc3986==2.0.0 rich==12.4.4 @@ -141,7 +141,7 @@ termcolor==1.1.0 terminaltables==3.1.10 toml==0.10.2 tomli==2.0.1 -tornado==6.2 +tornado==6.3.3 tox==3.25.1 tqdm==4.64.0 traitlets==5.3.0 @@ -155,3 +155,4 @@ w3lib==1.22.0 wcwidth==0.2.5 webencodings==0.5.1 zipp==3.8.0 +setuptools>=65.5.1 # not directly required, pinned by Snyk to avoid a vulnerability