From 46c7b8f49f7e8ab20120df76b7e2b97e8fb0315c Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 12 Jan 2026 11:00:46 +0000 Subject: [PATCH] fix: backend_app/requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871873 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871876 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871877 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871888 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871929 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871954 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871979 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14872000 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-14896210 --- backend_app/requirements.txt | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/backend_app/requirements.txt b/backend_app/requirements.txt index 2bf1eff..83de25e 100644 --- a/backend_app/requirements.txt +++ b/backend_app/requirements.txt @@ -1,4 +1,4 @@ -aiohttp==3.8.1 +aiohttp==3.13.3 amqp==2.5.2 asgiref==3.3.4 async-timeout==4.0.1 @@ -67,7 +67,7 @@ supervisor==4.1.0 tqdm==4.56.0 typing-extensions==3.7.4.3 uritemplate==3.0.1 -urllib3==1.26.5 +urllib3==2.6.3 vine==1.3.0 yarl==1.4.2 zipp==0.6.0