From 50608bb7fb2e18deeea006a311c0d922f306bd85 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Tue, 25 Jan 2022 16:19:42 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-CELERY-2314953 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2329158 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2329159 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-2329160 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-2329135 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-2331901 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-2331905 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-2331907 - https://snyk.io/vuln/SNYK-PYTHON-WAGTAIL-2342656 --- requirements.txt | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/requirements.txt b/requirements.txt index 5f32d953..7b5a5315 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,6 +1,6 @@ -wagtail==2.12.5 +wagtail==2.15.2 boto==2.49.0 -celery==4.4.2 +celery==5.2.2 django_compressor==2.4 django-storages==1.8 django-libsass==0.8 @@ -27,3 +27,5 @@ gunicorn==20.0.4 # Tests django-nose==1.4.6 factory_boy==2.12.0 +django>=3.2.11 # not directly required, pinned by Snyk to avoid a vulnerability +pillow>=9.0.0 # not directly required, pinned by Snyk to avoid a vulnerability