From 8b82fa62e0b867b10bf8486eee434155e6fc031c Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sat, 21 May 2022 03:25:02 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-PYJWT-2840625 --- requirements.txt | 1 + 1 file changed, 1 insertion(+) diff --git a/requirements.txt b/requirements.txt index 98c9c0dd..87833ab5 100644 --- a/requirements.txt +++ b/requirements.txt @@ -101,3 +101,4 @@ memento_client>=0.5.1,!=0.6.0 # pywikibot prefers using the inbuilt bz2 module if python was compiled with # bz2 support. But if it wasn't, bz2file is used instead. # bz2file +pyjwt>=2.4.0 # not directly required, pinned by Snyk to avoid a vulnerability