From 6fa68b67b4ba312c34b1f2df13d1b59bb3bb2ab8 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 3 Sep 2025 04:03:02 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-NUMPY-2321964 - https://snyk.io/vuln/SNYK-PYTHON-NUMPY-2321966 - https://snyk.io/vuln/SNYK-PYTHON-NUMPY-2321969 - https://snyk.io/vuln/SNYK-PYTHON-NUMPY-2321970 - https://snyk.io/vuln/SNYK-PYTHON-PROTOBUF-10364902 --- requirements.txt | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index 145097b..9ecdbdd 100644 --- a/requirements.txt +++ b/requirements.txt @@ -3,7 +3,7 @@ html5lib==1.0.1 matplotlib-3.3.3 mysql-connector==2.2.9 mysql-connector-python==8.0.21 -numpy==1.18.5 +numpy==1.22.2 pipwin==0.4.9 PyPrind==2.11.2 PyQt5==5.15.1 @@ -12,3 +12,4 @@ requests==2.23.0 selenium==3.141.0 urllib3==1.25.9 +protobuf>=4.25.8 # not directly required, pinned by Snyk to avoid a vulnerability