10 Commits

Author SHA1 Message Date
Alvin
97cc5beaff Merge pull request #4 from Alvin-Zilverstand/snyk-fix-ecc43c463bbebc06e33eff689c96a19a
[Snyk] Fix for 4 vulnerabilities
2026-03-24 13:12:56 +01:00
Alvin
9f8fdb9363 Merge branch 'main' into snyk-fix-ecc43c463bbebc06e33eff689c96a19a 2026-03-24 13:12:45 +01:00
Alvin
0fd2988620 Merge pull request #5 from Alvin-Zilverstand/snyk-fix-f0842a9b6702b40a57cc1e6854b0881b
[Snyk] Fix for 9 vulnerabilities
2026-03-24 11:27:53 +01:00
snyk-bot
d4d1634bd7 fix: requirements.txt to reduce vulnerabilities
The following vulnerabilities are fixed by pinning transitive dependencies:
- https://snyk.io/vuln/SNYK-PYTHON-CERTIFI-5805047
- https://snyk.io/vuln/SNYK-PYTHON-FLASK-15322678
- https://snyk.io/vuln/SNYK-PYTHON-GUNICORN-6615672
- https://snyk.io/vuln/SNYK-PYTHON-JINJA2-6809379
- https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-6928867
- https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-7448482
- https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-6002459
- https://snyk.io/vuln/SNYK-PYTHON-WERKZEUG-6035177
- https://snyk.io/vuln/SNYK-PYTHON-ZIPP-7430899
2026-03-24 10:26:01 +00:00
snyk-bot
7a10268e97 fix: requirements.txt to reduce vulnerabilities
The following vulnerabilities are fixed by pinning transitive dependencies:
- https://snyk.io/vuln/SNYK-PYTHON-CERTIFI-7430173
- https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-7448482
- https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-9964606
- https://snyk.io/vuln/SNYK-PYTHON-ZIPP-7430899
2026-03-23 10:40:22 +00:00
Alvin
fa00f20901 Merge pull request #3 from Alvin-Zilverstand/snyk-fix-e644bc4c26ef531b4c5a69f67f9bff9a
[Snyk] Fix for 11 vulnerabilities
2026-03-23 11:39:21 +01:00
snyk-bot
c73fbb7a4c fix: requirements.txt to reduce vulnerabilities
The following vulnerabilities are fixed by pinning transitive dependencies:
- https://snyk.io/vuln/SNYK-PYTHON-CERTIFI-3164749
- https://snyk.io/vuln/SNYK-PYTHON-FLASK-5490129
- https://snyk.io/vuln/SNYK-PYTHON-GUNICORN-7856105
- https://snyk.io/vuln/SNYK-PYTHON-IDNA-6597975
- https://snyk.io/vuln/SNYK-PYTHON-JINJA2-6150717
- https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6043904
- https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-5595532
- https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-3180412
- https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-5926907
- https://snyk.io/vuln/SNYK-PYTHON-WERKZEUG-3319935
- https://snyk.io/vuln/SNYK-PYTHON-WERKZEUG-3319936
2026-03-23 10:38:57 +00:00
snyk-bot
9f5d49fcc7 fix: requirements.txt to reduce vulnerabilities
The following vulnerabilities are fixed by pinning transitive dependencies:
- https://snyk.io/vuln/SNYK-PYTHON-CERTIFI-3164749
- https://snyk.io/vuln/SNYK-PYTHON-FLASK-5490129
- https://snyk.io/vuln/SNYK-PYTHON-GUNICORN-7856105
- https://snyk.io/vuln/SNYK-PYTHON-IDNA-6597975
- https://snyk.io/vuln/SNYK-PYTHON-JINJA2-6150717
- https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6043904
- https://snyk.io/vuln/SNYK-PYTHON-REQUESTS-5595532
- https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-3180412
- https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-5926907
- https://snyk.io/vuln/SNYK-PYTHON-WERKZEUG-3319935
- https://snyk.io/vuln/SNYK-PYTHON-WERKZEUG-3319936
2026-03-23 09:49:02 +00:00
Alvin
6ba4dc8986 Merge pull request #2 from Alvin-Zilverstand/snyk-fix-2831f1de1d8b8f1474f4cce91a587096
[Snyk] Security upgrade python from 3.14.3 to 3.15-rc-slim-trixie
2026-03-18 14:04:22 +01:00
snyk-bot
26fb29c6d0 fix: Dockerfile to reduce vulnerabilities
The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-DEBIAN13-IMAGEMAGICK-15339506
- https://snyk.io/vuln/SNYK-DEBIAN13-IMAGEMAGICK-15339525
- https://snyk.io/vuln/SNYK-DEBIAN13-IMAGEMAGICK-15339527
- https://snyk.io/vuln/SNYK-DEBIAN13-IMAGEMAGICK-15339557
- https://snyk.io/vuln/SNYK-DEBIAN13-IMAGEMAGICK-15339582
2026-03-18 13:03:50 +00:00
2 changed files with 12 additions and 9 deletions

View File

@@ -1,6 +1,6 @@
# syntax=docker/dockerfile:1
FROM python:3.14.3
FROM python:3.15-rc-slim-trixie
WORKDIR /api

View File

@@ -1,17 +1,20 @@
autopep8==1.6.0
certifi==2020.6.20
certifi==2024.7.4
chardet==3.0.4
click==7.1.2
Flask==1.1.4
gunicorn==20.1.0
idna==2.10
Flask==3.1.3
gunicorn==22.0.0
idna==3.7
itsdangerous==1.1.0
Jinja2==2.11.3
Jinja2==3.1.4
MarkupSafe==2.0.1
pycodestyle==2.8.0
python-dotenv==0.14.0
requests==2.28.1
requests==2.32.2
toml==0.10.2
urllib3==1.26.12
Werkzeug==1.0.1
urllib3==1.26.18
Werkzeug==2.3.8
colorthief==0.2.1
pillow>=10.0.0 # not directly required, pinned by Snyk to avoid a vulnerability
setuptools>=78.1.1 # not directly required, pinned by Snyk to avoid a vulnerability
zipp>=3.19.1 # not directly required, pinned by Snyk to avoid a vulnerability