From 63fba94ebcfe15fea1892f0f2eead06a987ed4b5 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 19 Dec 2025 10:50:00 +0000 Subject: [PATCH] fix: backend/classifier/requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-FILELOCK-14458335 - https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-10305723 - https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-6928867 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-10390194 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-14192442 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-14192443 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-7267250 - https://snyk.io/vuln/SNYK-PYTHON-ZIPP-7430899 --- backend/classifier/requirements.txt | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/backend/classifier/requirements.txt b/backend/classifier/requirements.txt index 6198b06..5e30579 100644 --- a/backend/classifier/requirements.txt +++ b/backend/classifier/requirements.txt @@ -13,4 +13,8 @@ tldextract>=3.4.0 # spaCy small English model (installable via pip from GitHub release) https://github.com/explosion/spacy-models/releases/download/en_core_web_sm-3.7.0/en_core_web_sm-3.7.0.tar.gz#egg=en_core_web_sm # Test tooling -pytest>=7.0.0 \ No newline at end of file +pytest>=7.0.0 +filelock>=3.20.1 # not directly required, pinned by Snyk to avoid a vulnerability +requests>=2.32.4 # not directly required, pinned by Snyk to avoid a vulnerability +urllib3>=2.6.0 # not directly required, pinned by Snyk to avoid a vulnerability +zipp>=3.19.1 # not directly required, pinned by Snyk to avoid a vulnerability \ No newline at end of file