Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

⬆️ Updates pillow to v6.2.2 #63

Merged
merged 1 commit into from
Jan 2, 2020
Merged

⬆️ Updates pillow to v6.2.2 #63

merged 1 commit into from
Jan 2, 2020

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Jan 2, 2020

This PR contains the following updates:

Package Update Change
pillow (source) patch ==6.2.1 -> ==6.2.2

Release Notes

python-pillow/Pillow

v6.2.2

Compare Source

  • This is the last Pillow release to support Python 2.7 #​3642

  • Overflow checks for realloc for tiff decoding. CVE TBD
    [wiredfool, radarhere]

  • Catch SGI buffer overrun. CVE TBD
    [radarhere]

  • Catch PCX P mode buffer overrun. CVE TBD
    [radarhere]

  • Catch FLI buffer overrun. CVE TBD
    [radarhere]

  • Raise an error for an invalid number of bands in FPX image. CVE-2019-19911
    [wiredfool, radarhere]


Renovate configuration

📅 Schedule: At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻️ Rebasing: Whenever PR becomes conflicted, or if you modify the PR title to begin with "rebase!".

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

Newsflash: Renovate has joined WhiteSource, and is now free for all use. Learn more or view updated terms and privacy policies.

@frenck frenck merged commit a334695 into master Jan 2, 2020
@frenck frenck deleted the renovate/pillow-6.x branch January 2, 2020 12:38
@addons-assistant
Copy link

This thread has been automatically locked because it has not had recent activity. Please open a new issue for related bugs and link to relevant comments in this thread.

@addons-assistant addons-assistant bot locked as resolved and limited conversation to collaborators Feb 1, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants