From e780892b8cb69187608700b4587108dad52ed31a Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sat, 31 Jan 2026 08:21:09 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-PROTOBUF-15090738 --- requirements.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index 5b11b4c..beaf64e 100644 --- a/requirements.txt +++ b/requirements.txt @@ -2,5 +2,5 @@ rook>=0.1.209 flask>=1.0,<=2.0 -e git+https://github.com/Rookout/python-flask.git@e56318f9c84978ecdaeaaff4aa819dc86f5509c7#egg=Flask_OpenTracing jaeger-client -protobuf>=3.18.3 # not directly required, pinned by Snyk to avoid a vulnerability +protobuf>=6.33.5 # not directly required, pinned by Snyk to avoid a vulnerability werkzeug==2.3.7