Skip to content

fix(security): update root Pillow dependency - #2726

Closed
0xjohnnydev wants to merge 1 commit into
mainfrom
agent/security-python-root-pillow-20260731
Closed

fix(security): update root Pillow dependency#2726
0xjohnnydev wants to merge 1 commit into
mainfrom
agent/security-python-root-pillow-20260731

Conversation

@0xjohnnydev

Copy link
Copy Markdown
Contributor

What users see

The repository's root Python lockfile resolves Pillow 12.2.0. GitHub Dependabot reports multiple security advisories for that version.

What changed

Validation

  • uv lock --check passed.
  • Confirmed the root lockfile resolves Pillow 12.3.0 with no older root Pillow resolution.
  • git diff --check passed.

Definition of Done

  • Every visible root Pillow alert is mapped to this focused draft.
  • The root lock graph resolves outside the reported vulnerable range.
  • A maintainer reviews and advances this draft; this automation will not merge or mark it ready.
  • GitHub closes the alerts after the reviewed fix reaches the default branch.

@0xjohnnydev

Copy link
Copy Markdown
Contributor Author

Closing this draft because its root Pillow update is now included in draft #2719. #2719 updates both GitPython and Pillow in the single root Python lockfile and validates them together. Nothing was merged or marked ready.

@0xjohnnydev 0xjohnnydev closed this Aug 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant