From 31b1d84284f82a966892035846ef8e03ea249d3b Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 26 Jul 2023 21:49:15 +0000 Subject: [PATCH] fix: tools/ci_build/github/linux/docker/manylinux2014_build_scripts/requirements-tools.txt to reduce vulnerabilities The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-CERTIFI-5805047 --- .../docker/manylinux2014_build_scripts/requirements-tools.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tools/ci_build/github/linux/docker/manylinux2014_build_scripts/requirements-tools.txt b/tools/ci_build/github/linux/docker/manylinux2014_build_scripts/requirements-tools.txt index bbd2c995488c1..1fca2d07bef8f 100644 --- a/tools/ci_build/github/linux/docker/manylinux2014_build_scripts/requirements-tools.txt +++ b/tools/ci_build/github/linux/docker/manylinux2014_build_scripts/requirements-tools.txt @@ -1,6 +1,6 @@ # pip requirements for tools # NOTE: certifi has GPG signatures; could download and verify independently. -certifi==2020.12.5 \ +certifi==2023.7.22 \ --hash=sha256:719a74fb9e33b9bd44cc7f3a8d94bc35e4049deebe19ba7d8e108280cfd59830 \ --hash=sha256:1a4995114262bffbc2413b159f2a1a480c969de6e6eb13ee966d470af86af59c auditwheel==3.3.1 \