From 3148704e75905ba5036d3599cf98af3a49802008 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 18 Nov 2024 05:54:43 +0000 Subject: [PATCH] fix: test-requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-BANDIT-6241859 - https://snyk.io/vuln/SNYK-PYTHON-ZIPP-7430899 --- test-requirements.txt | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/test-requirements.txt b/test-requirements.txt index 7eb48af72e..8a68d6f5bf 100644 --- a/test-requirements.txt +++ b/test-requirements.txt @@ -19,6 +19,7 @@ requests-mock>=1.2.0 # Apache-2.0 keystonemiddleware>=4.17.0 # Apache-2.0 # Security checks -bandit>=1.1.0 # Apache-2.0 +bandit>=1.7.7 # Apache-2.0 docutils>=0.11 # OSI-Approved Open Source, Public Domain +zipp>=3.19.1 # not directly required, pinned by Snyk to avoid a vulnerability