[Snyk] Security upgrade pillow from 9.5.0 to 12.3.0#706
Conversation
The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-17972376 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-17972377 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-17972384 - https://snyk.io/vuln/SNYK-PYTHON-PILLOW-17972386
|
This major version upgrade from Pillow 9.5.0 to 12.3.0 includes several significant breaking changes that require code modifications and environment updates. Key Breaking Changes:
Recommendation: This upgrade requires significant developer action. Before merging, you must:
Source: Pillow Changelog [1, 5]
|
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #706 +/- ##
=======================================
Coverage 99.54% 99.54%
=======================================
Files 101 101
Lines 17426 17426
Branches 1430 1430
=======================================
Hits 17347 17347
Misses 29 29
Partials 50 50
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Snyk has created this PR to fix 4 vulnerabilities in the pip dependencies of this project.
Snyk changed the following file(s):
requirements-dev.txtBreaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Out-of-bounds Write
🦉 Out-of-bounds Read
🦉 Allocation of Resources Without Limits or Throttling