Bump pillow from 8.1.0 to 8.1.1 #177

Merged
hansegucker merged 1 commit from dependabot/pip/pillow-8.1.1 into dev 2021-03-03 09:17:40 +01:00
Owner

Created by: dependabot-preview[bot]

Bumps pillow from 8.1.0 to 8.1.1.

Release notes

Sourced from pillow's releases.

8.1.1

https://pillow.readthedocs.io/en/stable/releasenotes/8.1.1.html

Changelog

Sourced from pillow's changelog.

8.1.1 (2020-03-01)

  • Use more specific regex chars to prevent ReDoS. CVE-2021-25292 [hugovk]
  • Fix OOB Read in TiffDecode.c, and check the tile validity before reading. CVE-2021-25291 [wiredfool]
  • Fix negative size read in TiffDecode.c. CVE-2021-25290 [wiredfool]
  • Fix OOB read in SgiRleDecode.c. CVE-2021-25293 [wiredfool]
  • Incorrect error code checking in TiffDecode.c. CVE-2021-25289 [wiredfool]
  • PyModule_AddObject fix for Python 3.10 #5194 [radarhere]
Commits
  • 741d874 8.1.1 version bump
  • 179cd1c Added 8.1.1 release notes to index
  • 7d29665 Update CHANGES.rst [ci skip]
  • d25036f Credits
  • 973a4c3 Release notes for 8.1.1
  • 521dab9 Use more specific regex chars to prevent ReDoS
  • 8b8076b Fix for CVE-2021-25291
  • e25be1e Fix negative size read in TiffDecode.c
  • f891baa Fix OOB read in SgiRleDecode.c
  • cbfdde7 Incorrect error code checking in TiffDecode.c
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Pull request limits (per update run and/or open at any time)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)
*Created by: dependabot-preview[bot]* Bumps [pillow](https://github.com/python-pillow/Pillow) from 8.1.0 to 8.1.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/python-pillow/Pillow/releases">pillow's releases</a>.</em></p> <blockquote> <h2>8.1.1</h2> <p><a href="https://pillow.readthedocs.io/en/stable/releasenotes/8.1.1.html">https://pillow.readthedocs.io/en/stable/releasenotes/8.1.1.html</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/python-pillow/Pillow/blob/master/CHANGES.rst">pillow's changelog</a>.</em></p> <blockquote> <h1>8.1.1 (2020-03-01)</h1> <ul> <li>Use more specific regex chars to prevent ReDoS. CVE-2021-25292 [hugovk]</li> <li>Fix OOB Read in TiffDecode.c, and check the tile validity before reading. CVE-2021-25291 [wiredfool]</li> <li>Fix negative size read in TiffDecode.c. CVE-2021-25290 [wiredfool]</li> <li>Fix OOB read in SgiRleDecode.c. CVE-2021-25293 [wiredfool]</li> <li>Incorrect error code checking in TiffDecode.c. CVE-2021-25289 [wiredfool]</li> <li>PyModule_AddObject fix for Python 3.10 <a href="https://github-redirect.dependabot.com/python-pillow/Pillow/issues/5194">#5194</a> [radarhere]</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/python-pillow/Pillow/commit/741d8744a54bedbc49f16922c61a06fcb3681f53"><code>741d874</code></a> 8.1.1 version bump</li> <li><a href="https://github.com/python-pillow/Pillow/commit/179cd1c8f94aabc47e9e522e01683ea9aadbd3a5"><code>179cd1c</code></a> Added 8.1.1 release notes to index</li> <li><a href="https://github.com/python-pillow/Pillow/commit/7d296653da045e18b379c991797f933e054a7476"><code>7d29665</code></a> Update CHANGES.rst [ci skip]</li> <li><a href="https://github.com/python-pillow/Pillow/commit/d25036fca7c8658b698492088361453bb20073e2"><code>d25036f</code></a> Credits</li> <li><a href="https://github.com/python-pillow/Pillow/commit/973a4c333ab6d603e82f6eb2aa6f39d1cfcecccb"><code>973a4c3</code></a> Release notes for 8.1.1</li> <li><a href="https://github.com/python-pillow/Pillow/commit/521dab94c7ab72b037bd9a83e9663401e0fd2cee"><code>521dab9</code></a> Use more specific regex chars to prevent ReDoS</li> <li><a href="https://github.com/python-pillow/Pillow/commit/8b8076bdcb3815be0ef0d279651d8d1342b8ea61"><code>8b8076b</code></a> Fix for CVE-2021-25291</li> <li><a href="https://github.com/python-pillow/Pillow/commit/e25be1e33dc526bfd1094bc778a54d8e29bf66c9"><code>e25be1e</code></a> Fix negative size read in TiffDecode.c</li> <li><a href="https://github.com/python-pillow/Pillow/commit/f891baa604636cd2506a9360d170bc2cf4963cc5"><code>f891baa</code></a> Fix OOB read in SgiRleDecode.c</li> <li><a href="https://github.com/python-pillow/Pillow/commit/cbfdde7b1f2295059a20a539ee9960f0bec7b299"><code>cbfdde7</code></a> Incorrect error code checking in TiffDecode.c</li> <li>Additional commits viewable in <a href="https://github.com/python-pillow/Pillow/compare/8.1.0...8.1.1">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://api.dependabot.com/badges/compatibility_score?dependency-name=pillow&package-manager=pip&previous-version=8.1.0&new-version=8.1.1)](https://dependabot.com/compatibility-score/?dependency-name=pillow&package-manager=pip&previous-version=8.1.0&new-version=8.1.1) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language - `@dependabot badge me` will comment on this PR with code to add a "Dependabot enabled" badge to your readme Additionally, you can set the following in your Dependabot [dashboard](https://app.dependabot.com): - Update frequency (including time of day and day of week) - Pull request limits (per update run and/or open at any time) - Out-of-range updates (receive only lockfile updates, if desired) - Security updates (receive only security updates, if desired) </details>
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
aleksis/AlekSIS-App-Plank!177
No description provided.