From 10c7a56131d81a8e942aea25dd2fa7c58aa4a6b0 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 10 Oct 2022 01:46:45 +0000 Subject: [PATCH] fix: data-pipeline/requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-PYYAML-42159 - https://snyk.io/vuln/SNYK-PYTHON-PYYAML-559098 - https://snyk.io/vuln/SNYK-PYTHON-PYYAML-590151 --- data-pipeline/requirements.txt | 1 + 1 file changed, 1 insertion(+) diff --git a/data-pipeline/requirements.txt b/data-pipeline/requirements.txt index 3df1bf2c..9e91c258 100644 --- a/data-pipeline/requirements.txt +++ b/data-pipeline/requirements.txt @@ -13,3 +13,4 @@ awscli<1.14.0 JSONBender aiohttp pytz +pyyaml>=5.4 # not directly required, pinned by Snyk to avoid a vulnerability