From 94b613bca96d123bef37aac002a618d4c6d34b0e Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sat, 1 Jun 2024 02:13:14 +0000 Subject: [PATCH] fix: requirements_dev.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-PYMONGO-7172112 --- requirements_dev.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/requirements_dev.txt b/requirements_dev.txt index c02036c50d..6ed8de9146 100644 --- a/requirements_dev.txt +++ b/requirements_dev.txt @@ -5,7 +5,7 @@ mock==3.0.5 # PyMongo and Athena dependencies are needed for some of the unit tests: # (this is not perfect and we should resolve this in a different way) -pymongo[srv,tls]==3.9.0 +pymongo==4.6.3 botocore>=1.13,<1.14.0 PyAthena>=1.5.0 ptvsd==4.3.2