fix: requirements.txt to reduce vulnerabilities

The following vulnerabilities are fixed by pinning transitive dependencies:
- https://snyk.io/vuln/SNYK-PYTHON-CERTIFI-7430173
- https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-7448482
- https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-9964606
- https://snyk.io/vuln/SNYK-PYTHON-ZIPP-7430899
This commit is contained in:
snyk-bot
2026-03-23 10:40:22 +00:00
parent fa00f20901
commit 7a10268e97

View File

@@ -1,5 +1,5 @@
autopep8==1.6.0 autopep8==1.6.0
certifi==2022.12.7 certifi==2024.7.4
chardet==3.0.4 chardet==3.0.4
click==7.1.2 click==7.1.2
Flask==2.2.5 Flask==2.2.5
@@ -16,4 +16,5 @@ urllib3==1.26.17
Werkzeug==2.2.3 Werkzeug==2.2.3
colorthief==0.2.1 colorthief==0.2.1
pillow>=10.0.0 # not directly required, pinned by Snyk to avoid a vulnerability pillow>=10.0.0 # not directly required, pinned by Snyk to avoid a vulnerability
setuptools>=65.5.1 # not directly required, pinned by Snyk to avoid a vulnerability setuptools>=78.1.1 # not directly required, pinned by Snyk to avoid a vulnerability
zipp>=3.19.1 # not directly required, pinned by Snyk to avoid a vulnerability