From 7aa384d77042602f6e37414d304199de8e9dc462 Mon Sep 17 00:00:00 2001 From: Owen Littlejohns <owen.m.littlejohns@nasa.gov> Date: Mon, 6 Nov 2023 12:39:30 -0500 Subject: [PATCH 1/3] Add .snyk file. --- .snyk | 4 ++++ 1 file changed, 4 insertions(+) create mode 100644 .snyk diff --git a/.snyk b/.snyk new file mode 100644 index 0000000..d4c3c62 --- /dev/null +++ b/.snyk @@ -0,0 +1,4 @@ +# Snyk (https://snyk.io) policy file, primarily to set the specific minor +# version of Python to use while scanning requirements files. +language-settings: + python: "3.9" From b152fdb2e48f5afaf4e9e03dfe63d2ee4f91a802 Mon Sep 17 00:00:00 2001 From: Owen Littlejohns <owen.m.littlejohns@nasa.gov> Date: Mon, 6 Nov 2023 12:46:29 -0500 Subject: [PATCH 2/3] Unpin sub-dependency for true test. --- requirements/dev.txt | 1 - 1 file changed, 1 deletion(-) diff --git a/requirements/dev.txt b/requirements/dev.txt index 6735ee5..f2a8429 100644 --- a/requirements/dev.txt +++ b/requirements/dev.txt @@ -7,4 +7,3 @@ moto ~= 4.2.7 pytest ~= 7.4.3 python-dotenv ~=1.0.0 safety ~= 2.3.5 -werkzeug ~= 3.0.1 # Dependency of moto, pinned to mitigate vulnerability. From b539b1d9b46cb8e333f2920307f03f0646e60a44 Mon Sep 17 00:00:00 2001 From: Owen Littlejohns <owen.m.littlejohns@nasa.gov> Date: Mon, 6 Nov 2023 12:48:44 -0500 Subject: [PATCH 3/3] Move .snyk to requirements directory. --- .snyk => requirements/.snyk | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename .snyk => requirements/.snyk (100%) diff --git a/.snyk b/requirements/.snyk similarity index 100% rename from .snyk rename to requirements/.snyk