see: https://github.com/LetsMesh/Site/security/dependabot?q=is%3Aopen+manifest%3APipfile.lock+package%3ADjango