From f2bb543875c9b7a0a0d4a41cffcc65fdad2272a5 Mon Sep 17 00:00:00 2001 From: kevinlinglesas <36995745+kevinlinglesas@users.noreply.github.com> Date: Tue, 23 Mar 2021 21:00:19 -0400 Subject: [PATCH] Update jinja2 version to >=2.11.3 GitHub dependabot tagged viya4-ark repo for jinja2 vulnerability based on ReDos issue https://github.com/advisories/GHSA-g3rq-g295-4j3m (CVE-2020-28493). --- requirements.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index c726cec..7134517 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,3 +1,3 @@ -Jinja2==2.11.2 +jinja2>=2.11.3 Pint==0.11 requests==2.22.0