From 092b110f2e922423eb93c7e753fab528fc93538c Mon Sep 17 00:00:00 2001 From: snyk-bot <snyk-bot@snyk.io> Date: Wed, 28 Sep 2022 21:01:31 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-LXML-2316995 - https://snyk.io/vuln/SNYK-PYTHON-LXML-2940874 --- requirements.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index c48100af3ce..8a52c4317b0 100644 --- a/requirements.txt +++ b/requirements.txt @@ -11,7 +11,7 @@ gunicorn==20.1.0 httpx==0.18.2 internetarchive==2.3.0 isbnlib==3.10.6 -lxml==4.6.3 +lxml==4.9.1 Pillow==9.0.0 psycopg2==2.8.6 pydantic==1.9.0