Files
peikarband/requirements.txt
Ehsan.Asadi 92d6715aea
Some checks failed
ci/woodpecker/push/woodpecker Pipeline failed
CD - Build & Deploy / build-and-push (push) Has been cancelled
CD - Build & Deploy / package-helm (push) Has been cancelled
CD - Build & Deploy / deploy-staging (push) Has been cancelled
CD - Build & Deploy / deploy-production (push) Has been cancelled
CD - Build & Deploy / release (push) Has been cancelled
CI / security (push) Has been cancelled
CI / test (3.11) (push) Has been cancelled
CI / test (3.12) (push) Has been cancelled
security: fix CVE-2025-55182 + update dependencies (security)
- Upgrade reflex 0.4.0 → 0.8.24.post1 to mitigate React Server Components RCE vulnerability (CVE-2025-55182, CVSS 10.0)
- Fix python-ovh package name: python-ovh → ovh (1.2.0) for Python 3.11 compatibility
- Refs: https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components

ApprovalToken: ۲
2025-12-30 15:32:15 +03:30

92 lines
2.3 KiB
Plaintext

# Peikarband Platform - Core Dependencies
# ============================================
# Core Framework
# ============================================
reflex==0.8.24.post1 # Updated for security (CVE-2025-55182)
# ============================================
# Database & ORM
# ============================================
sqlalchemy==2.0.23
psycopg2-binary==2.9.9
alembic==1.13.0
# ============================================
# Data Validation
# ============================================
pydantic==2.5.2
pydantic-settings==2.1.0
email-validator==2.1.0
# ============================================
# Caching
# ============================================
redis==5.0.1
# ============================================
# Task Queue
# ============================================
celery==5.3.4
flower==2.0.1
# ============================================
# Security & Authentication
# ============================================
passlib[bcrypt]==1.7.4
pyjwt==2.8.0
pyotp==2.9.0
cryptography==41.0.7
# ============================================
# Cloud Provider APIs
# ============================================
python-digitalocean==1.17.0
hcloud==1.33.2
ovh==1.2.0 # Correct package name (not python-ovh)
# ============================================
# Payment Gateways
# ============================================
zarinpal==1.0.0
idpay==1.0.0
# ============================================
# HTTP Client
# ============================================
httpx==0.25.2
requests==2.31.0
# ============================================
# Logging
# ============================================
structlog==23.2.0
python-json-logger==2.0.7
# ============================================
# Monitoring & Error Tracking
# ============================================
sentry-sdk==1.38.0
prometheus-client==0.19.0
# ============================================
# Utilities
# ============================================
python-decouple==3.8
python-dotenv==1.0.0
tenacity==8.2.3
python-multipart==0.0.6
psutil==5.9.6
# ============================================
# Server Management
# ============================================
paramiko==3.4.0
fabric==3.2.2
# ============================================
# Date & Time
# ============================================
python-dateutil==2.8.2
pytz==2023.3