Bump pillow from 7.1.2 to 9.3.0 in /backend/admin/pyspark_docker/pyspark_scripts/analysis#74
Conversation
Bumps [pillow](https://github.com/python-pillow/Pillow) from 7.1.2 to 9.3.0. - [Release notes](https://github.com/python-pillow/Pillow/releases) - [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst) - [Commits](python-pillow/Pillow@7.1.2...9.3.0) --- updated-dependencies: - dependency-name: pillow dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
| pathtools==0.1.2 | ||
| pickleshare==0.7.5 | ||
| Pillow==7.1.2 | ||
| Pillow==9.3.0 |
There was a problem hiding this comment.
mistune 0.8.4 / requirements.txt
Total vulnerabilities: 1
| Critical: 0 | High: 1 | Medium: 0 | Low: 0 |
|---|
| Vulnerability ID | Severity | CVSS | Fixed in | Status |
|---|---|---|---|---|
| CVE-2022-34749 | 7.5 | 2.0.3 |
Open |
| pathtools==0.1.2 | ||
| pickleshare==0.7.5 | ||
| Pillow==7.1.2 | ||
| Pillow==9.3.0 |
There was a problem hiding this comment.
click 7.1.2 / requirements.txt
Total vulnerabilities: 1
| Critical: 0 | High: 0 | Medium: 1 | Low: 0 |
|---|
| Vulnerability ID | Severity | CVSS | Fixed in | Status |
|---|---|---|---|---|
| PRISMA-2021-0020 | - | 8.0.0 |
Open |
| pathtools==0.1.2 | ||
| pickleshare==0.7.5 | ||
| Pillow==7.1.2 | ||
| Pillow==9.3.0 |
There was a problem hiding this comment.
numpy 1.18.5 / requirements.txt
Total vulnerabilities: 1
| Critical: 0 | High: 0 | Medium: 1 | Low: 0 |
|---|
| Vulnerability ID | Severity | CVSS | Fixed in | Status |
|---|---|---|---|---|
| CVE-2021-34141 | 5.3 | 1.22.0 |
Open |
| pathtools==0.1.2 | ||
| pickleshare==0.7.5 | ||
| Pillow==7.1.2 | ||
| Pillow==9.3.0 |
There was a problem hiding this comment.
certifi 2020.4.5.1 / requirements.txt
Total vulnerabilities: 1
| Critical: 0 | High: 0 | Medium: 0 | Low: 1 |
|---|
| Vulnerability ID | Severity | CVSS | Fixed in | Status |
|---|---|---|---|---|
| CVE-2022-23491 | 4 | 2022.12.07 |
Open |
| pathtools==0.1.2 | ||
| pickleshare==0.7.5 | ||
| Pillow==7.1.2 | ||
| Pillow==9.3.0 |
There was a problem hiding this comment.
jinja2 2.11.2 / requirements.txt
Total vulnerabilities: 1
| Critical: 0 | High: 0 | Medium: 1 | Low: 0 |
|---|
| Vulnerability ID | Severity | CVSS | Fixed in | Status |
|---|---|---|---|---|
| CVE-2020-28493 | 5.3 | 2.11.3 |
Open |
| pathtools==0.1.2 | ||
| pickleshare==0.7.5 | ||
| Pillow==7.1.2 | ||
| Pillow==9.3.0 |
There was a problem hiding this comment.
bleach 3.1.5 / requirements.txt
Total vulnerabilities: 1
| Critical: 0 | High: 0 | Medium: 1 | Low: 0 |
|---|
| Vulnerability ID | Severity | CVSS | Fixed in | Status |
|---|---|---|---|---|
| CVE-2021-23980 | 6.1 | 3.3.0 |
Open |
| pathtools==0.1.2 | ||
| pickleshare==0.7.5 | ||
| Pillow==7.1.2 | ||
| Pillow==9.3.0 |
There was a problem hiding this comment.
pygments 2.6.1 / requirements.txt
Total vulnerabilities: 2
| Critical: 0 | High: 2 | Medium: 0 | Low: 0 |
|---|
| Vulnerability ID | Severity | CVSS | Fixed in | Status |
|---|---|---|---|---|
| CVE-2021-20270 | 7 | 2.7.4 |
Open | |
| CVE-2021-27291 | 7 | 2.7.4 |
Open |
| pathtools==0.1.2 | ||
| pickleshare==0.7.5 | ||
| Pillow==7.1.2 | ||
| Pillow==9.3.0 |
There was a problem hiding this comment.
nbconvert 5.6.1 / requirements.txt
Total vulnerabilities: 1
| Critical: 0 | High: 0 | Medium: 1 | Low: 0 |
|---|
| Vulnerability ID | Severity | CVSS | Fixed in | Status |
|---|---|---|---|---|
| CVE-2021-32862 | 5.4 | 6.3.0 |
Open |
| pathtools==0.1.2 | ||
| pickleshare==0.7.5 | ||
| Pillow==7.1.2 | ||
| Pillow==9.3.0 |
| pathtools==0.1.2 | ||
| pickleshare==0.7.5 | ||
| Pillow==7.1.2 | ||
| Pillow==9.3.0 |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
26 similar comments
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
7 similar comments
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
Bumps pillow from 7.1.2 to 9.3.0.
Release notes
Sourced from pillow's releases.
... (truncated)
Changelog
Sourced from pillow's changelog.
... (truncated)
Commits
d594f4cUpdate CHANGES.rst [ci skip]909dc649.3.0 version bump1a51ce7Merge pull request #6699 from hugovk/security-libtiff_buffer2444cddMerge pull request #6700 from hugovk/security-samples_per_pixel-sec744f455Added release notes0846bfaAdd to release notes799a6a0Fix linting00b25fdHide UserWarning in logs05b175eTighter test case13f2c5aPrevent DOS with large SAMPLESPERPIXEL in Tiff IFDDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.