Skip to content

Updated constraints due security reasons (triggered on 2026-03-02T12:16:02+00:00 by 6f7c9813281a23ee269beca8b8cf998db0566123)#17

Open
github-actions[bot] wants to merge 1 commit intoexecfrom
create-pull-request/patch-audit-constraints
Open

Updated constraints due security reasons (triggered on 2026-03-02T12:16:02+00:00 by 6f7c9813281a23ee269beca8b8cf998db0566123)#17
github-actions[bot] wants to merge 1 commit intoexecfrom
create-pull-request/patch-audit-constraints

Conversation

@github-actions
Copy link

@github-actions github-actions bot commented Mar 2, 2026

Dependency issues not solved for Python 3.9

Name Version ID Fix Versions Description
pillow 11.3.0 GHSA-cfh3-3jmp-rvhc 12.1.1 ### Impact An out-of-bounds write may be triggered when loading a specially crafted PSD image. Pillow >= 10.3.0 users are affected. ### Patches Pillow 12.1.1 will be released shortly with a fix for this. ### Workarounds Image.open() has a formats parameter that can be used to prevent PSD images from being opened. ### References Pillow 12.1.1 will add release notes at https://pillow.readthedocs.io/en/stable/releasenotes/index.html

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant