From dc687c080372fc6d394f8fef259e68f2f6cbe897 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 21 May 2024 06:15:20 +0000 Subject: [PATCH 1/2] --- updated-dependencies: - dependency-name: requests dependency-type: direct:production ... Signed-off-by: dependabot[bot] --- packages/syftcli/setup.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/packages/syftcli/setup.py b/packages/syftcli/setup.py index 61a4ec2a424..c1de84afd26 100644 --- a/packages/syftcli/setup.py +++ b/packages/syftcli/setup.py @@ -5,7 +5,7 @@ __version__ = "0.1.11" packages = [ - "requests==2.31.0", + "requests==2.32.0", "pyyaml==6.0.1", "packaging==21.3", "typer[all]==0.9.0", From a262de4a26d57bce00f2591fc06afc9c46fb8d13 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Tue, 21 May 2024 22:35:04 +0000 Subject: [PATCH 2/2] fix: docs/requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-6928867 --- docs/requirements.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/requirements.txt b/docs/requirements.txt index 6f3176dae92..a16817917de 100644 --- a/docs/requirements.txt +++ b/docs/requirements.txt @@ -4,7 +4,7 @@ jinja2>=3.1.3 # not directly required, pinned by Snyk to avoid a vulnerability markupsafe==2.0.1 pydata-sphinx-theme==0.7.2 pygments>=2.15.0 # not directly required, pinned by Snyk to avoid a vulnerability -requests>=2.31.0 # not directly required, pinned by Snyk to avoid a vulnerability +requests>=2.32.0 # not directly required, pinned by Snyk to avoid a vulnerability setuptools>=65.5.1 # not directly required, pinned by Snyk to avoid a vulnerability sphinx==4.3.0 sphinx-autoapi==1.8.4