Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Pillow version due to CVE with 10.1 #487

Merged
merged 1 commit into from
Feb 13, 2024
Merged

Conversation

jysheng123
Copy link
Contributor

Issue #, if available:
https://github.com/aws/aws-sam-cli-app-templates/security/dependabot/235

Description of changes:
Pillow has a CVE with version 10.1.0. I checked in our repo and our pillow dependencies are all not fixed or 10.2.0 which is patched except for one runtime, Python3.8. I think we can bump this version because I see in the Pillow docs that 10.2.0 is supported or Python3.8

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@jysheng123 jysheng123 requested a review from a team as a code owner February 13, 2024 18:09
@jysheng123 jysheng123 requested review from mndeveci and bentvelj and removed request for a team February 13, 2024 18:09
@github-actions github-actions bot added pr/external stage/needs-triage Automatically applied to new issues and PRs, indicating they haven't been looked at. labels Feb 13, 2024
@jysheng123 jysheng123 added this pull request to the merge queue Feb 13, 2024
Merged via the queue into master with commit 6c53630 Feb 13, 2024
45 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
pr/external stage/needs-triage Automatically applied to new issues and PRs, indicating they haven't been looked at.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants