From bf6e9e2385a0395b89019fd49fd90d00fb06470a Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sun, 22 Sep 2024 17:45:26 +0000 Subject: [PATCH] fix: src/recommendationservice/requirements.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-GRPCIO-5834443 - https://snyk.io/vuln/SNYK-PYTHON-OPENTELEMETRYINSTRUMENTATION-5926995 - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-3180412 - https://snyk.io/vuln/SNYK-PYTHON-SETUPTOOLS-7448482 - https://snyk.io/vuln/SNYK-PYTHON-ZIPP-7430899 --- src/recommendationservice/requirements.txt | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/src/recommendationservice/requirements.txt b/src/recommendationservice/requirements.txt index 85d0901cde..d8d7d90ac0 100644 --- a/src/recommendationservice/requirements.txt +++ b/src/recommendationservice/requirements.txt @@ -1,7 +1,10 @@ grpcio-health-checking==1.43.0 -grpcio==1.51.3 +grpcio==1.53.2 opentelemetry-distro==0.36b0 opentelemetry-exporter-otlp-proto-grpc==1.15.0 python-dotenv==0.21.0 python-json-logger==2.0.4 psutil==5.9.2 # Importing this will also import opentelemetry-instrumentation-system-metrics when running opentelemetry-bootstrap +opentelemetry-instrumentation>=0.41b0 # not directly required, pinned by Snyk to avoid a vulnerability +setuptools>=70.0.0 # not directly required, pinned by Snyk to avoid a vulnerability +zipp>=3.19.1 # not directly required, pinned by Snyk to avoid a vulnerability