From 7ff42cba699b6dd54d799aeee7602ad4329e35dd Mon Sep 17 00:00:00 2001 From: Alessio Fabiani Date: Sun, 14 Apr 2024 10:55:44 +0200 Subject: [PATCH] [Snyk] Security upgrade idna from 3.6 to 3.7 (#12153) * fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-IDNA-6597975 * - Align setup.cfg to requirements.txt * - Align setup.cfg to requirements.txt --------- Co-authored-by: snyk-bot --- requirements.txt | 2 +- setup.cfg | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/requirements.txt b/requirements.txt index 4a7fd79827f..e2a67a2aea1 100644 --- a/requirements.txt +++ b/requirements.txt @@ -9,7 +9,7 @@ amqp==5.2.0 beautifulsoup4==4.12.3 httplib2<0.22.1 hyperlink==21.0.0 -idna>=2.5,<3.7 +idna>=2.5,<4 urllib3==1.26.18 Paver==1.3.4 python-slugify==8.0.4 diff --git a/setup.cfg b/setup.cfg index 9581097a55e..cc9a1824b63 100644 --- a/setup.cfg +++ b/setup.cfg @@ -35,7 +35,7 @@ install_requires = beautifulsoup4==4.12.3 httplib2<0.22.1 hyperlink==21.0.0 - idna>=2.5,<3.7 + idna>=2.5,<4 urllib3==1.26.18 Paver==1.3.4 python-slugify==8.0.4