Skip to content

Updated constraints due security reasons (triggered on 2026-03-16T12:22:21+00:00 by 6f7c9813281a23ee269beca8b8cf998db0566123)#17

Merged
jmfernandez merged 1 commit intoexecfrom
create-pull-request/patch-audit-constraints
Mar 19, 2026
Merged

Updated constraints due security reasons (triggered on 2026-03-16T12:22:21+00:00 by 6f7c9813281a23ee269beca8b8cf998db0566123)#17
jmfernandez merged 1 commit intoexecfrom
create-pull-request/patch-audit-constraints

Conversation

@github-actions
Copy link
Copy Markdown

@github-actions github-actions Bot commented Mar 2, 2026

Dependency issues not solved for Python 3.9

Name Version ID Fix Versions Description
pillow 11.3.0 GHSA-cfh3-3jmp-rvhc 12.1.1 ### Impact An out-of-bounds write may be triggered when loading a specially crafted PSD image. Pillow >= 10.3.0 users are affected. ### Patches Pillow 12.1.1 will be released shortly with a fix for this. ### Workarounds Image.open() has a formats parameter that can be used to prevent PSD images from being opened. ### References Pillow 12.1.1 will add release notes at https://pillow.readthedocs.io/en/stable/releasenotes/index.html

@github-actions github-actions Bot force-pushed the create-pull-request/patch-audit-constraints branch from f5080a2 to 4cfdb83 Compare March 9, 2026 12:16
@github-actions github-actions Bot changed the title Updated constraints due security reasons (triggered on 2026-03-02T12:16:02+00:00 by 6f7c9813281a23ee269beca8b8cf998db0566123) Updated constraints due security reasons (triggered on 2026-03-09T12:16:31+00:00 by 6f7c9813281a23ee269beca8b8cf998db0566123) Mar 9, 2026
@github-actions github-actions Bot force-pushed the create-pull-request/patch-audit-constraints branch from 4cfdb83 to 59a9090 Compare March 16, 2026 12:22
@github-actions github-actions Bot changed the title Updated constraints due security reasons (triggered on 2026-03-09T12:16:31+00:00 by 6f7c9813281a23ee269beca8b8cf998db0566123) Updated constraints due security reasons (triggered on 2026-03-16T12:22:21+00:00 by 6f7c9813281a23ee269beca8b8cf998db0566123) Mar 16, 2026
@jmfernandez jmfernandez merged commit dd2d6f8 into exec Mar 19, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant