Commit f5c0a2c
authored
chore(deps): bump pillow, django, uv to patch security vulnerabilities (#213)
* chore(deps): bump pillow from 12.1.1 to 12.2.0 in /requirements
Fixes GHSA-whj4-6x5x-4v2j (CVE-2026-40192): FITS GZIP decompression bomb
in Pillow. Affected versions: >= 10.3.0, < 12.2.0.
* chore(deps): bump django to 6.0.4 and uv to 0.11.7
Fixes pip-audit findings blocking CI:
- django 6.0.3 -> 6.0.4: CVE-2026-33033, CVE-2026-33034, CVE-2026-4292,
CVE-2026-4277, CVE-2026-3902
- uv 0.10.8 -> 0.11.7: GHSA-pjjw-68hj-v9mw1 parent 23856f7 commit f5c0a2c
2 files changed
Lines changed: 3 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
142 | 142 | | |
143 | 143 | | |
144 | 144 | | |
145 | | - | |
| 145 | + | |
146 | 146 | | |
147 | 147 | | |
148 | 148 | | |
| |||
212 | 212 | | |
213 | 213 | | |
214 | 214 | | |
215 | | - | |
| 215 | + | |
216 | 216 | | |
217 | 217 | | |
218 | 218 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
117 | 117 | | |
118 | 118 | | |
119 | 119 | | |
120 | | - | |
| 120 | + | |
121 | 121 | | |
122 | 122 | | |
123 | 123 | | |
| |||
0 commit comments