From f522d2fdd9e1c7047f555fb6e6a5d68696a95a9d Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Tue, 16 Jul 2024 07:50:48 +0000 Subject: [PATCH] fix: requirements/base.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-7448482 --- requirements/base.txt | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/requirements/base.txt b/requirements/base.txt index 6232c47d..3d99be1a 100644 --- a/requirements/base.txt +++ b/requirements/base.txt @@ -25,4 +25,5 @@ s2sphere < 0.3 scikit-learn >= 1.2, < 2 shapely >= 1, < 3 tqdm >= 4, < 5 -xmltodict < 0.14 \ No newline at end of file +xmltodict < 0.14 +setuptools>=70.0.0 # not directly required, pinned by Snyk to avoid a vulnerability \ No newline at end of file