Skip to content

Updated constraints due security reasons (triggered on 2026-03-16T12:22:21+00:00 by 6f7c9813281a23ee269beca8b8cf998db0566123)#17

Open
github-actions[bot] wants to merge 1 commit intoexecfrom
create-pull-request/patch-audit-constraints
Open

Updated constraints due security reasons (triggered on 2026-03-16T12:22:21+00:00 by 6f7c9813281a23ee269beca8b8cf998db0566123)#17
github-actions[bot] wants to merge 1 commit intoexecfrom
create-pull-request/patch-audit-constraints

Conversation

@github-actions
Copy link

@github-actions github-actions bot commented Mar 2, 2026

Dependency issues not solved for Python 3.9

Name Version ID Fix Versions Description
pillow 11.3.0 GHSA-cfh3-3jmp-rvhc 12.1.1 ### Impact An out-of-bounds write may be triggered when loading a specially crafted PSD image. Pillow >= 10.3.0 users are affected. ### Patches Pillow 12.1.1 will be released shortly with a fix for this. ### Workarounds Image.open() has a formats parameter that can be used to prevent PSD images from being opened. ### References Pillow 12.1.1 will add release notes at https://pillow.readthedocs.io/en/stable/releasenotes/index.html

@github-actions github-actions bot force-pushed the create-pull-request/patch-audit-constraints branch from f5080a2 to 4cfdb83 Compare March 9, 2026 12:16
@github-actions github-actions bot changed the title Updated constraints due security reasons (triggered on 2026-03-02T12:16:02+00:00 by 6f7c9813281a23ee269beca8b8cf998db0566123) Updated constraints due security reasons (triggered on 2026-03-09T12:16:31+00:00 by 6f7c9813281a23ee269beca8b8cf998db0566123) Mar 9, 2026
@github-actions github-actions bot force-pushed the create-pull-request/patch-audit-constraints branch from 4cfdb83 to 59a9090 Compare March 16, 2026 12:22
@github-actions github-actions bot changed the title Updated constraints due security reasons (triggered on 2026-03-09T12:16:31+00:00 by 6f7c9813281a23ee269beca8b8cf998db0566123) Updated constraints due security reasons (triggered on 2026-03-16T12:22:21+00:00 by 6f7c9813281a23ee269beca8b8cf998db0566123) Mar 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant