Bump pillow from 8.1.1 to 8.1.2 #179

Merged
hansegucker merged 1 commit from dependabot/pip/pillow-8.1.2 into dev 2021-03-08 11:03:23 +01:00
Owner

Created by: dependabot-preview[bot]

Bumps pillow from 8.1.1 to 8.1.2.

Release notes

Sourced from pillow's releases.

8.1.2

https://pillow.readthedocs.io/en/stable/releasenotes/8.1.2.html

Changelog

Sourced from pillow's changelog.

8.1.2 (2021-03-06)

  • Fix Memory DOS in BLP (CVE-2021-27921), ICNS (CVE-2021-27922) and ICO (CVE-2021-27923) Image Plugins [wiredfool]
Commits
  • 88bd672 8.1.2 version bump
  • d348636 Update CHANGES.rst [ci skip]
  • 2a66fa7 Added release notes for 8.1.2
  • 608bf4f Lint fix
  • 756fff3 Fix Memory DOS in Icns, Ico and Blp Image Plugins
  • 886ad5a Fix filename spelling
  • 0907fb1 Expanded "OOB" to "out-of-bounds" [ci skip]
  • c60c092 CHANGES.rst: update dates
  • 8fb5e50 Added more CVE numbers [ci skip]
  • a10d2c9 Updated spelling [ci skip]
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Pull request limits (per update run and/or open at any time)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)
*Created by: dependabot-preview[bot]* Bumps [pillow](https://github.com/python-pillow/Pillow) from 8.1.1 to 8.1.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/python-pillow/Pillow/releases">pillow's releases</a>.</em></p> <blockquote> <h2>8.1.2</h2> <p><a href="https://pillow.readthedocs.io/en/stable/releasenotes/8.1.2.html">https://pillow.readthedocs.io/en/stable/releasenotes/8.1.2.html</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/python-pillow/Pillow/blob/master/CHANGES.rst">pillow's changelog</a>.</em></p> <blockquote> <h1>8.1.2 (2021-03-06)</h1> <ul> <li>Fix Memory DOS in BLP (CVE-2021-27921), ICNS (CVE-2021-27922) and ICO (CVE-2021-27923) Image Plugins [wiredfool]</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/python-pillow/Pillow/commit/88bd672dafad68b419ea29bef941dfa17f941038"><code>88bd672</code></a> 8.1.2 version bump</li> <li><a href="https://github.com/python-pillow/Pillow/commit/d3486362da617a13ff44582eb609dc531e7e14c1"><code>d348636</code></a> Update CHANGES.rst [ci skip]</li> <li><a href="https://github.com/python-pillow/Pillow/commit/2a66fa7f2e4bdb463eb256cac1899dc33b3343de"><code>2a66fa7</code></a> Added release notes for 8.1.2</li> <li><a href="https://github.com/python-pillow/Pillow/commit/608bf4fef56af6a5811fff42111c4a3a0d8580a2"><code>608bf4f</code></a> Lint fix</li> <li><a href="https://github.com/python-pillow/Pillow/commit/756fff33128a0b643d10518a26ad04b726dd8973"><code>756fff3</code></a> Fix Memory DOS in Icns, Ico and Blp Image Plugins</li> <li><a href="https://github.com/python-pillow/Pillow/commit/886ad5a90e7ed8d962cae5114c44612c7a0cb578"><code>886ad5a</code></a> Fix filename spelling</li> <li><a href="https://github.com/python-pillow/Pillow/commit/0907fb13f41da461cbcb724d2127c693cae09dd4"><code>0907fb1</code></a> Expanded &quot;OOB&quot; to &quot;out-of-bounds&quot; [ci skip]</li> <li><a href="https://github.com/python-pillow/Pillow/commit/c60c09280ba83fa72744e00c2c83faa8b717284b"><code>c60c092</code></a> CHANGES.rst: update dates</li> <li><a href="https://github.com/python-pillow/Pillow/commit/8fb5e5035b9f5a1b5008a91e355e507bef8563ee"><code>8fb5e50</code></a> Added more CVE numbers [ci skip]</li> <li><a href="https://github.com/python-pillow/Pillow/commit/a10d2c950ade7c238f451e9425c9e1895758c44e"><code>a10d2c9</code></a> Updated spelling [ci skip]</li> <li>Additional commits viewable in <a href="https://github.com/python-pillow/Pillow/compare/8.1.1...8.1.2">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://api.dependabot.com/badges/compatibility_score?dependency-name=pillow&package-manager=pip&previous-version=8.1.1&new-version=8.1.2)](https://dependabot.com/compatibility-score/?dependency-name=pillow&package-manager=pip&previous-version=8.1.1&new-version=8.1.2) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language - `@dependabot badge me` will comment on this PR with code to add a "Dependabot enabled" badge to your readme Additionally, you can set the following in your Dependabot [dashboard](https://app.dependabot.com): - Update frequency (including time of day and day of week) - Pull request limits (per update run and/or open at any time) - Out-of-range updates (receive only lockfile updates, if desired) - Security updates (receive only security updates, if desired) </details>
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
aleksis/AlekSIS-App-Plank!179
No description provided.