Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

dependabot security bump pillow and urllib3 #221

Merged
merged 1 commit into from
Sep 29, 2021
Merged

Conversation

awsbmillare
Copy link
Contributor

@awsbmillare awsbmillare commented Sep 29, 2021

Issue #, if available:

Description of changes:

Bump pillow
CVE-2021-23437 Raise ValueError if color specifier is too long [hugovk, radarhere]

Bump urllib3
dependabot flag: #202

Couldn't just rely on dependabot since it did not update testing dependencies

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@awsbmillare awsbmillare merged commit 05a17e9 into master Sep 29, 2021
@awsbmillare awsbmillare deleted the bump_pillow_urllib3 branch September 29, 2021 15:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
2 participants