From a143cc59fab5ae83cfa96664b5f3e59066388ccc Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Tue, 13 Jan 2026 09:32:40 +0000 Subject: [PATCH] fix: requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871873 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871876 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871877 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871888 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871929 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871954 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14871979 - https://snyk.io/vuln/SNYK-PYTHON-AIOHTTP-14872000 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-14896210 --- requirements.txt | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index 6388a68b..9a30002e 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,5 +1,5 @@ aiofiles>=0.8.0 -aiohttp>=3.8.0 +aiohttp>=3.13.3 anthropic asyncio-mqtt docling @@ -10,3 +10,4 @@ pathlib2 PyPDF2>=2.0.0 reportlab>=3.5.0 streamlit +urllib3>=2.6.3 # not directly required, pinned by Snyk to avoid a vulnerability