pillow-simd icon indicating copy to clipboard operation
pillow-simd copied to clipboard

Update to 9.4.0 to fix security vulnerabilities

Open Dawars opened this issue 1 year ago • 3 comments

Recently several vulnerabilities have been uncovered. https://github.com/advisories?query=type%3Areviewed+Pillow

It is crucial to apply these fixes for use in production.

This PR is a straightforward merge from 9.4.x containing security vulnerability fixes, specifically:

  • https://github.com/python-pillow/Pillow/pull/6087
  • https://github.com/python-pillow/Pillow/pull/6269
  • https://github.com/python-pillow/Pillow/pull/6402
  • https://github.com/python-pillow/Pillow/pull/6699
  • https://github.com/python-pillow/Pillow/pull/6678
  • https://github.com/python-pillow/Pillow/pull/6700

Only test failing is test_file_fits:test_open which is caused by one-off error in simd implementation of rgb2l(). https://github.com/Dawars/pillow-simd/blob/simd/9.4.x/Tests/test_file_fits.py#L21

This seems negligible, how should I proceed?

The update also contains Github Actions related changes which I'm not familiar with and therefore probably incorrectly set up.

Dawars avatar Mar 14 '23 11:03 Dawars

Is this repo still alive ?

mrkiril94 avatar Aug 23 '23 11:08 mrkiril94

There's also a high-severity vulnerability in webp that was fixed in https://github.com/python-pillow/Pillow/pull/7395

gingerlime avatar Oct 11 '23 19:10 gingerlime

This changes are unrelated to Pillow-simd, which doesn’t have binary builds. It always uses system-provided versions of libraries

homm avatar Oct 12 '23 05:10 homm