From 1a5dcec32ecd866b24202752bd7c3176a8559c03 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 1 Feb 2024 18:06:21 +0000 Subject: [PATCH] fix: requirements/_requirements_base.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6219984 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6219986 --- requirements/_requirements_base.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/requirements/_requirements_base.txt b/requirements/_requirements_base.txt index 581c0c54..06add6b6 100644 --- a/requirements/_requirements_base.txt +++ b/requirements/_requirements_base.txt @@ -2,7 +2,7 @@ tqdm>=4.64 psutil>=5.9.0 numexpr>=2.8.3 opencv-python>=4.6.0.0 -pillow>=9.2.0 +pillow>=10.2.0 scikit-learn==1.0.2; python_version < '3.9' # AMD needs version 1.0.2 and 1.1.0 not available in Python 3.7 scikit-learn>=1.1.0; python_version >= '3.9' fastcluster>=1.2.6