From fb722fccaffd0f4bf4067e244fbd1db8befc4d8b Mon Sep 17 00:00:00 2001 From: Ian Hunter Date: Thu, 25 Jan 2024 12:33:54 +0000 Subject: [PATCH] fix: scripts/benchmark/requirements.txt to reduce vulnerabilities (#460) The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-6182918 Co-authored-by: snyk-bot --- scripts/benchmark/requirements.txt | 1 + 1 file changed, 1 insertion(+) diff --git a/scripts/benchmark/requirements.txt b/scripts/benchmark/requirements.txt index 65c1ef6bd..b7d520fe7 100644 --- a/scripts/benchmark/requirements.txt +++ b/scripts/benchmark/requirements.txt @@ -7,3 +7,4 @@ d20 numpy>=1.22.2 # not directly required, pinned by Snyk to avoid a vulnerability setuptools>=65.5.1 # not directly required, pinned by Snyk to avoid a vulnerability fonttools>=4.43.0 # not directly required, pinned by Snyk to avoid a vulnerability +pillow>=10.2.0 # not directly required, pinned by Snyk to avoid a vulnerability