From 46f34dca493cc32e650886926efd190388041ccc Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 30 Dec 2022 04:40:12 +0000 Subject: [PATCH] fix: requirements/base.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2329158 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2329159 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2329160 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2389002 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2389021 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2606966 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2606969 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2940618 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2968205 - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-3113904 - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-3180412 --- requirements/base.txt | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/requirements/base.txt b/requirements/base.txt index 31f018d0..f00bb2aa 100644 --- a/requirements/base.txt +++ b/requirements/base.txt @@ -1,4 +1,4 @@ -django==2.2.25 # Our web framework +django==3.2.15 # Our web framework django-countries==5.2 dj-database-url==0.4.1 gunicorn==20.1.0 # Python WSGI HTTP Server @@ -19,3 +19,4 @@ django_storages==1.7 # Hosting all the site images django-dotenv==1.4.1 # Read env variables from a file for DEV boto==2.48.0 # Talking to AWS flake8==3.5.0 # Python linter +setuptools>=65.5.1 # not directly required, pinned by Snyk to avoid a vulnerability