aquatix / imagine-gallery

Gallery site with `imagine` innards, based on Django
Apache License 2.0
1 stars 0 forks source link

[Snyk] Security upgrade bleach from 3.1.0 to 3.1.1 #14

Closed snyk-bot closed 2 years ago

snyk-bot commented 4 years ago

Snyk has created this PR to fix one or more vulnerable packages in the `pip` dependencies of this project.

Changes included in this PR

Vulnerabilities that will be fixed

By pinning:
Severity Issue Upgrade Breaking Change Exploit Maturity
medium severity Cross-site Scripting (XSS)
SNYK-PYTHON-BLEACH-552160
bleach:
3.1.0 -> 3.1.1
No No Known Exploit

Note that some vulnerabilities couldn’t be fully fixed, and so will still fail the Snyk test report.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:

🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic