whylogs
whylogs copied to clipboard
Pillow vulnerabilities
Description
There are multiple osv vulnerability issues with the Pillow 9.x package dependency. An update to 10.x (https://github.com/whylabs/whylogs/blob/mainline/python/pyproject.toml#L68) is currently not possible.
Some vulnerabilities:
- https://osv.dev/vulnerability/GHSA-3f63-hfp8-52jq
- https://osv.dev/GHSA-56pw-mpj4-fxww
- https://osv.dev/GHSA-8ghj-p4vj-mr35
Steps to reproduce:
-
poetry install
-
osv-scanner --lockfile poetry.lock
(https://github.com/google/osv-scanner)
Suggestions
Could we update Pillow to its latest version?
- [x] I have reviewed the Guidelines for Contributing and the Code of Conduct.
This issue is stale. Remove stale label or it will be closed next week.
changes merged to allow newer versions of PIL and updates lock file. Slated for next whylogs release, 1.4.1
released in version 1.4.1