[Snyk] Fix for 2 vulnerabilities - #9
Conversation
The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-AUTHLIB-16097396 - https://snyk.io/vuln/SNYK-PYTHON-MAKO-16098253
|
This upgrade includes a major version update for authlib@0.15.4 → authlib@1.6.11Risk: HIGH The upgrade to version 1.0.0 of
Recommendation: This is a significant upgrade that will require code modifications. Review the official changelog and your application's usage of the SQLAlchemy integration and JOSE APIs before merging. Source: Authlib Changelog mako@1.1.4 → mako@1.3.11Risk: MEDIUM This upgrade drops support for older Python versions.
Recommendation: Ensure your production environment is running Python 3.8 or a more recent version. Source: Mako Changelog
|
Snyk has created this PR to fix 2 vulnerabilities in the pip dependencies of this project.
Snyk changed the following file(s):
requirements.txtBreaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Cross-site Request Forgery (CSRF)
🦉 Directory Traversal