This repository was archived by the owner on Oct 9, 2021. It is now read-only.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to fix one or more vulnerable packages in the `pip` dependencies of this project.
Changes included in this PR
Vulnerabilities that will be fixed
By pinning:
SNYK-PYTHON-BABEL-1278589
babel:
2.6.0 -> 2.9.1
SNYK-PYTHON-GEVENT-40735
gevent:
1.1.2 -> 1.2a1
SNYK-PYTHON-JINJA2-1012994
jinja2:
2.10.1 -> 2.11.3
SNYK-PYTHON-LXML-1047473
lxml:
3.7.1 -> 4.6.2
SNYK-PYTHON-LXML-1047474
lxml:
3.7.1 -> 4.6.2
SNYK-PYTHON-LXML-1088006
lxml:
3.7.1 -> 4.6.2
SNYK-PYTHON-LXML-72651
lxml:
3.7.1 -> 4.6.2
SNYK-PYTHON-PASSLIB-569603
passlib:
1.7.1 -> 1.7.3
SNYK-PYTHON-PILLOW-1055461
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-1055462
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-1080635
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-1080654
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-1081494
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-1081501
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-1081502
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-1082329
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-1082750
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-1090584
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-1090586
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-1090587
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-1090588
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-1292150
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-1292151
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-1316216
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-1319443
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-536096
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-540746
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-541323
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-541324
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-541325
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-541326
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-574573
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-574574
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-574575
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-574576
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PILLOW-574577
pillow:
5.4.1 -> 8.1.0
SNYK-PYTHON-PSUTIL-483082
psutil:
5.6.6 -> 5.6.7
SNYK-PYTHON-REPORTLAB-1022145
reportlab:
3.5.13 -> 3.5.55
SNYK-PYTHON-REPORTLAB-473444
reportlab:
3.5.13 -> 3.5.55
SNYK-PYTHON-URLLIB3-1014645
urllib3:
1.24.3 -> 1.25.9
SNYK-PYTHON-URLLIB3-1533435
urllib3:
1.24.3 -> 1.25.9
Some vulnerabilities couldn't be fully fixed and so Snyk will still find them when the project is tested again. This may be because the vulnerability existed within more than one direct dependency, but not all of the effected dependencies could be upgraded.
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
🛠 Adjust project settings
📚 Read more about Snyk's upgrade and patch logic