aiohttp>=3.9.4 # CVE-2024-30251 ansi2html # Used to format the stdout from jobs into html for display asciichartpy asn1 azure-identity azure-keyvault boto3 botocore channels channels-redis cryptography<42.0.0 # investigation is needed for 42+ to work with OpenSSL v3.0.x (RHEL 9.4) and v3.2.x (RHEL 9.5) Cython daphne distro django==4.2.16 # CVE-2024-24680 django-cors-headers django-crum django-extensions django-guid django-oauth-toolkit<2.0.0 # Version 2.0.0 has breaking changes that will need to be worked out before upgrading django-polymorphic django-solo django-split-settings djangorestframework>=3.15.0 djangorestframework-yaml filelock GitPython>=3.1.37 # CVE-2023-41040 grpcio irc jinja2>=3.1.3 # CVE-2024-22195 JSON-log-formatter jsonschema Markdown # used for formatting API help maturin # pydantic-core build dep msgpack msrestazure openshift opentelemetry-api~=1.24 # new y streams can be drastically different, in a good way opentelemetry-sdk~=1.24 opentelemetry-instrumentation-logging opentelemetry-exporter-otlp pexpect==4.7.0 # see library notes prometheus_client psycopg psutil pygerduty pyopenssl>=23.2.0 # resolve dep conflict from cryptography pin above pyparsing==2.4.6 # Upgrading to v3 of pyparsing introduce errors on smart host filtering: Expected 'or' term, found 'or' (at char 15), (line:1, col:16) python-daemon>3.0.0 python-dsv-sdk>=1.0.4 python-tss-sdk>=1.2.1 pyyaml>=6.0.2 # require packing fix for cython 3 or higher pyzstd # otel collector log file compression library receptorctl sqlparse>=0.4.4 # Required by django https://github.com/ansible/awx/security/dependabot/96 redis[hiredis] requests slack-sdk twilio twisted[tls]>=23.10.0 # CVE-2023-46137 uWSGI uwsgitop wheel>=0.38.1 # CVE-2022-40898 pip==21.2.4 # see UPGRADE BLOCKERs setuptools<71.0.0 # see UPGRADE BLOCKERs, path hack in v71 breaks irc deps setuptools_scm[toml] # see UPGRADE BLOCKERs, xmlsec build dep setuptools-rust>=0.11.4 # cryptography build dep pkgconfig>=1.5.1 # xmlsec build dep - needed for offline build django-flags>=5.0.13 # Temporarily added to use ansible-runner from git branch, to be removed # when ansible-runner moves from requirements_git.txt to here pbr