LCORE-3161: bump Pillow 12.1.1 → 12.3.0 (CVE-2026-59205) - #2195
LCORE-3161: bump Pillow 12.1.1 → 12.3.0 (CVE-2026-59205)#2195platex-rehor-bot wants to merge 1 commit into
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
✨ Simplify code
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
/ok-to-test |
LCORE-3161 Pillow <12.3.0 has controlled native heap corruption in ImageCms.ImageCmsTransform.apply when output image mode mismatches the transform's declared output mode. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
b8a69ed to
ef1f0eb
Compare
|
Rebased on top of the latest |
|
/ok-to-test |
Description
Bumps Pillow from 12.1.1 to 12.3.0 to fix CVE-2026-59205 — controlled native heap corruption in
ImageCms.ImageCmsTransform.applywhen the output image mode does not match the transform's declared output mode.Changes:
Pillow>=12.3.0constraint inpyproject.toml(transitive dep from llama-stack/sentence-transformers)uv.lockwith Pillow 12.3.0 PyPI wheel hashes (cp312 + cp313).konflux/requirements.hashes.wheel.txtwith Pillow 12.3.0 RHOAI 3.5 wheel hashes (x86_64 + aarch64)Type of change
Tools used to create PR
Related Tickets & Documents
Checklist before requesting a review
Testing
pyproject.tomlconstraint is syntactically correctuv.lockhashes match PyPI JSON API for Pillow 12.3.0.konflux/requirements.hashes.wheel.txthashes match RHOAI 3.5 index for Pillow 12.3.0