From 1222df95a807298dcb604b2ae1a48e1a5b19e0dc Mon Sep 17 00:00:00 2001 From: Glenn Jocher Date: Mon, 22 Jul 2024 23:48:32 +0200 Subject: [PATCH] [Snyk] Security upgrade zipp from 3.15.0 to 3.19.1 (#2256) fix: utils/google_app_engine/additional_requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-ZIPP-7430899 Co-authored-by: snyk-bot --- utils/google_app_engine/additional_requirements.txt | 1 + 1 file changed, 1 insertion(+) diff --git a/utils/google_app_engine/additional_requirements.txt b/utils/google_app_engine/additional_requirements.txt index 821c3caf3c..08c276f7b4 100644 --- a/utils/google_app_engine/additional_requirements.txt +++ b/utils/google_app_engine/additional_requirements.txt @@ -3,3 +3,4 @@ pip==23.3 Flask==2.3.2 gunicorn==22.0.0 werkzeug>=3.0.1 # not directly required, pinned by Snyk to avoid a vulnerability +zipp>=3.19.1 # not directly required, pinned by Snyk to avoid a vulnerability