From 2cdf93c30fc612db09a5005978764d17a1ca5f8b Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Tue, 9 Jul 2024 16:09:04 +0000 Subject: [PATCH] fix: requirements_bundles.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-ZIPP-7430899 --- requirements_bundles.txt | 1 + 1 file changed, 1 insertion(+) diff --git a/requirements_bundles.txt b/requirements_bundles.txt index 1151ca65ac..1db9bd1779 100644 --- a/requirements_bundles.txt +++ b/requirements_bundles.txt @@ -6,3 +6,4 @@ # These can be removed when upgrading to Python 3.x importlib-metadata==4.12.0 # remove when on 3.8 importlib_resources==1.5 # remove when on 3.9 +zipp>=3.19.1 # not directly required, pinned by Snyk to avoid a vulnerability