From fd422de07ec241e0a5253b53df7813ab1ed8a5d1 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 20 Aug 2025 12:07:23 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-KERAS-11775502 - https://snyk.io/vuln/SNYK-PYTHON-PROTOBUF-10364902 - https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-10305723 - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-9964606 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-10390194 --- requirements.txt | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/requirements.txt b/requirements.txt index 973a16c..d483f9d 100644 --- a/requirements.txt +++ b/requirements.txt @@ -13,7 +13,7 @@ grpcio==1.32.0 h5py==2.10.0 idna==2.10 joblib==1.0.0 -Keras==2.4.3 +Keras==3.11.0 Keras-Preprocessing==1.1.2 Markdown==3.3.3 nltk==3.5 @@ -22,12 +22,12 @@ oauthlib==3.1.0 opencv-python==4.5.1.48 opt-einsum==3.3.0 Pillow==8.1.0 -protobuf==3.14.0 +protobuf==4.25.8 pyasn1==0.4.8 pyasn1-modules==0.2.8 PyYAML==5.4.1 regex==2020.11.13 -requests==2.25.1 +requests==2.32.4 requests-oauthlib==1.3.0 rsa==4.7 scipy==1.6.0 @@ -39,6 +39,7 @@ tensorflow-estimator==2.4.0 termcolor==1.1.0 tqdm==4.56.0 typing-extensions==3.7.4.3 -urllib3==1.26.3 +urllib3==2.5.0 Werkzeug==1.0.1 wrapt==1.12.1 +setuptools>=78.1.1 # not directly required, pinned by Snyk to avoid a vulnerability