Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

dependabot security bump pillow and urllib3 #222

Merged
merged 4 commits into from
Sep 29, 2021

Conversation

awsbmillare
Copy link
Contributor

Issue #, if available:

Description of changes:

Bump pillow
CVE-2021-23437 Raise ValueError if color specifier is too long [hugovk, radarhere]

Bump urllib3
dependabot flag: #202

Couldn't just rely on dependabot since it did not update testing dependencies

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@awsbmillare awsbmillare merged commit ba794f1 into 1.2-2 Sep 29, 2021
@mabunday mabunday deleted the bump_pillow_urllib3_1.2-2 branch August 4, 2022 20:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
1 participant