From a7d4066ea607d925f030ae25210d141bfdabcfac Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 21 Feb 2024 16:22:01 +0000 Subject: [PATCH] fix: leaktopus_backend/requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-CELERY-2314953 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3172287 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3314966 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3315324 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3315328 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3315331 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3315452 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3315972 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3315975 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3316038 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-3316211 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-5663682 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-5777683 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-5813745 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-5813746 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-5813750 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-5914629 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6036192 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6050294 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6092044 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6126975 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6149518 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6157248 - https://snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-6210214 - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-3180412 - https://snyk.io/vuln/SNYK-PYTHON-WERKZEUG-3319935 - https://snyk.io/vuln/SNYK-PYTHON-WERKZEUG-3319936 - https://snyk.io/vuln/SNYK-PYTHON-WERKZEUG-6035177 --- leaktopus_backend/requirements.txt | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/leaktopus_backend/requirements.txt b/leaktopus_backend/requirements.txt index 7ccf918..e4dfd58 100644 --- a/leaktopus_backend/requirements.txt +++ b/leaktopus_backend/requirements.txt @@ -2,7 +2,7 @@ jinja2<3.1.0 Flask==1.1.2 itsdangerous==2.0.1 # Flask_Caching==1.9.0 -Werkzeug==1.0.1 +Werkzeug==2.3.8 flask_debugtoolbar==0.11.0 # flask_mail==0.9.1 # flask_static_digest==0.2.1 @@ -20,7 +20,7 @@ loguru==0.6.0 # Data and workers. redis==3.5.3 -celery==5.0.5 +celery==5.2.2 # Tool specific libs. PyGithub>=1.55 @@ -28,7 +28,7 @@ elasticsearch==7.17.4 GitPython truffleHog==2.2.1 pyjwt>=2.4.0 # not directly required, pinned to avoid a vulnerability -cryptography==39 +cryptography==42.0.2 # Documentation libs flasgger==0.9.5 @@ -41,3 +41,4 @@ pytest-cov==4.0.0 requests_cache==0.9.8 pytest-httpserver==1.0.0 +setuptools>=65.5.1 # not directly required, pinned by Snyk to avoid a vulnerability