From 1ce6823318ed9dda649e517f05d3c040ebf1d2db Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 12 Feb 2024 02:42:34 +0000 Subject: [PATCH 1/2] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-DNSPYTHON-6241713 --- requirements.txt | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index e1d2620..39008b6 100644 --- a/requirements.txt +++ b/requirements.txt @@ -5,4 +5,5 @@ requests~=2.31.0 pymongo~=4.3.3 waitress~=2.1.2 colorlog~=6.7.0 -bleach~=6.0.0 \ No newline at end of file +bleach~=6.0.0 +dnspython>=2.6.0rc1 # not directly required, pinned by Snyk to avoid a vulnerability \ No newline at end of file From 261228bbd44f9f46443ee89ebf0a553fc118b276 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 21 Feb 2024 04:36:07 +0000 Subject: [PATCH 2/2] fix: Dockerfile to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-ALPINE318-EXPAT-6241039 - https://snyk.io/vuln/SNYK-ALPINE318-EXPAT-6241040 --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 61af026..a948111 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,4 @@ -FROM python:3.13.0a3-alpine3.18 +FROM python:3.13.0a4-alpine3.18 RUN apk upgrade && apk add curl && apk upgrade busybox # CVE-2022-48174