[Snyk] Fix for 6 vulnerabilities - #11
Conversation
The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-PROTOBUF-10364902 - https://snyk.io/vuln/SNYK-PYTHON-PYASN1-15032639 - https://snyk.io/vuln/SNYK-PYTHON-PYASN1-15674561 - https://snyk.io/vuln/SNYK-PYTHON-PYASN1-17972379 - https://snyk.io/vuln/SNYK-PYTHON-PYASN1-17972380 - https://snyk.io/vuln/SNYK-PYTHON-PYASN1-17972383
|
This upgrade includes two packages. The primary change to review is the minor version upgrade for pyasn1 0.5.1 → 0.6.4 (Medium Risk) This upgrade introduces several notable changes:
Recommendation: protobuf 4.24.4 → 4.25.8 (Low Risk) This is a minor version upgrade within the same major version. The changes primarily consist of bug fixes and performance improvements. No significant breaking changes were identified in the release notes for this range. [12, 15]
|
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Snyk has created this PR to fix 6 vulnerabilities in the pip dependencies of this project.
Snyk changed the following file(s):
requirements.txtBreaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Uncontrolled Recursion
🦉 Allocation of Resources Without Limits or Throttling