-
-
Notifications
You must be signed in to change notification settings - Fork 14.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
python3Packages.pillow: 8.0.1 -> 8.1.0 #111655
Conversation
That should go trough staging because the amounts of rebuilds. The diff won't apply cleanly because pillow got converted into a generic.nix file for pilleow-simd. |
Hah, funny. I checked the last pillow update that was pullrequested and that was in the 100-500 region. That was only a year ago. |
The url does not resolve anymore and after checking the current LICENSE at https://github.com/python-pillow/Pillow/blob/master/LICENSE it states that it is simply the HPND license. > Like PIL, Pillow is licensed under the open source HPND License:
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
diff LGTM
Motivation for this change
https://github.com/python-pillow/Pillow/blob/master/CHANGES.rst#810-2020-01-02
Fixes: CVE-2020-35654, CVE-2020-35653, CVE-2020-35655
Things done
sandbox
innix.conf
on non-NixOS linux)nix-shell -p nixpkgs-review --run "nixpkgs-review wip"
./result/bin/
)nix path-info -S
before and after)