Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

build(deps): bump pillow version 10.2 for fix security vulnerability #6689

Merged
merged 1 commit into from Jan 24, 2024

Conversation

onuralpszr
Copy link
Contributor

@onuralpszr onuralpszr commented Jan 23, 2024

Hello @squidfunk I notice that you were using pillow version 9.4 and it has security problems and recently dependabot also gives me warning about security problems listed in here.

GHSA-j7hp-h8jx-5ppr
GHSA-8vj2-vxx3-667w
GHSA-hhrh-69hc-fgg7

libwebp: OOB write in BuildHuffmanTable
Arbitrary Code Execution in Pillow
Pillow Denial of Service vulnerability

I also notice that minimum python 3.8 and using pillow 10.2 also going keep that version so it should be fine as well. I also build docs and in my tests it was also works fine as well.

Thank you.

Signed-off-by: Onuralp SEZER <thunderbirdtr@gmail.com>
@squidfunk
Copy link
Owner

Thanks!

@squidfunk squidfunk merged commit 3a6b592 into squidfunk:master Jan 24, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants