浏览代码

dependabot fix for jinja2

Rodja Trappe 1 年之前
父节点
当前提交
fd5e30f208
共有 2 个文件被更改,包括 2 次插入2 次删除
  1. 1 1
      poetry.lock
  2. 1 1
      pyproject.toml

+ 1 - 1
poetry.lock

@@ -2684,4 +2684,4 @@ plotly = ["plotly"]
 [metadata]
 lock-version = "2.0"
 python-versions = "^3.8"
-content-hash = "34ac8ab7fa3d0431e4810904d7cb95b50e7bab4b3683515fed644d38bfaa7dd9"
+content-hash = "7de9e029cfe07dc1abc8b3fdf162c71190f991b417e4c647f664de7bef0910be"

+ 1 - 1
pyproject.toml

@@ -18,7 +18,7 @@ fastapi = ">=0.109.0,<0.110.0"
 python-socketio = ">=5.10.0" # https://github.com/zauberzeug/nicegui/issues/1809
 vbuild = ">=0.8.2"
 watchfiles = ">=0.18.1,<1.0.0"
-jinja2 = "^3.1.2"
+jinja2 = "^3.1.3" # https://github.com/zauberzeug/nicegui/security/dependabot/24
 python-multipart = "^0.0.6"
 orjson = {version = "^3.8.6", markers = "platform_machine != 'i386' and platform_machine != 'i686'"} # orjson does not support 32bit
 itsdangerous = "^2.1.2"