From 631b4c3ffab03a49bf99902fd6dcfbfcfe0ec458 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 3 May 2024 14:38:41 +0000 Subject: [PATCH] fix: solidity_deposit_contract/web3_tester/requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-ETHABI-6085292 - https://snyk.io/vuln/SNYK-PYTHON-ETHABI-6394102 - https://snyk.io/vuln/SNYK-PYTHON-ETHACCOUNT-2988803 - https://snyk.io/vuln/SNYK-PYTHON-ETHKEYFILE-2391482 - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-3180412 - https://snyk.io/vuln/SNYK-PYTHON-WEBSOCKETS-1297182 - https://snyk.io/vuln/SNYK-PYTHON-WEBSOCKETS-1582792 --- solidity_deposit_contract/web3_tester/requirements.txt | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/solidity_deposit_contract/web3_tester/requirements.txt b/solidity_deposit_contract/web3_tester/requirements.txt index 8dadab0bc2..b2234cfc58 100644 --- a/solidity_deposit_contract/web3_tester/requirements.txt +++ b/solidity_deposit_contract/web3_tester/requirements.txt @@ -3,3 +3,8 @@ web3==5.4.0 pytest==3.6.1 # The eth2spec ../../ +eth-abi>=5.0.1 # not directly required, pinned by Snyk to avoid a vulnerability +eth-account>=0.5.9 # not directly required, pinned by Snyk to avoid a vulnerability +eth-keyfile>=0.6.0 # not directly required, pinned by Snyk to avoid a vulnerability +setuptools>=65.5.1 # not directly required, pinned by Snyk to avoid a vulnerability +websockets>=10.0 # not directly required, pinned by Snyk to avoid a vulnerability