From 0e39d1cba32705c220be290de6854f253b320657 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 9 Jan 2026 09:16:26 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871873 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871876 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871877 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871888 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871929 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871954 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871979 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14872000 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-14896210 --- requirements.txt | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/requirements.txt b/requirements.txt index 79861421..e3402999 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,4 +1,4 @@ -aiohttp==3.6.2 +aiohttp==3.13.3 async-timeout==3.0.0 attrs==18.1.0 Babel==2.6.0 @@ -40,7 +40,7 @@ social-auth-app-django==2.1.0 social-auth-core==1.7.0 SQLAlchemy==1.3.11 Unidecode==1.0.22 -urllib3==1.23 +urllib3==2.6.3 websockets==6.0 yarl==1.2.6 youtube-dl==2019.11.22