From eff8c16cbdc2effa85b9103d2b4a3df6f19eab0d Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 2 Feb 2024 03:13:01 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6219984 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6219986 --- requirements.txt | 1 + 1 file changed, 1 insertion(+) diff --git a/requirements.txt b/requirements.txt index 43d997511..81ecfef4f 100644 --- a/requirements.txt +++ b/requirements.txt @@ -4,3 +4,4 @@ rasa==2.8.21 # NB! when updating, make sure to also update: -r actions/requirements-actions.txt pytablewriter python-dotenv~=0.15.0 +pillow>=10.2.0 # not directly required, pinned by Snyk to avoid a vulnerability