Skip to content
This repository was archived by the owner on Sep 23, 2026. It is now read-only.

fix(deps): bump pillow to 12.2.0 for CVE-2026-25990 - #2187

Merged
7Sageer merged 4 commits into
MoonshotAI:mainfrom
farmer-data:fix/pillow-12.2.0
May 12, 2026
Merged

7Sageer merged 4 commits into
MoonshotAI:mainfrom
farmer-data:fix/pillow-12.2.0

Conversation

@farmer-data

@farmer-data farmer-data commented May 8, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Bumps pillow from 12.1.0 → 12.2.0 to address CVE-2026-25990 (out-of-bounds write when loading PSD images), which blocks installs in security-tight environments.

Closes #2153.

Test plan

  • uv lock regenerates cleanly
  • prek run (format + check) passes locally
  • CI green on this PR

Open in Devin Review

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Open in Devin Review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: bd5874b082

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread pyproject.toml
"loguru>=0.6.0,<0.8",
"prompt-toolkit==3.0.52",
"pillow==12.1.0",
"pillow==12.2.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Bump the package minor version for this change

This dependency/security fix changes the released package contents, but the project remains at 1.41.0. The repo instruction in AGENTS.md says, “Minor version is bumped for any change: new features, improvements, bug fixes, etc.” and “Patch version is always 0,” so this change should also bump the root package version (and the lockfile package metadata) to the next minor before release.

Useful? React with 👍 / 👎.

@farmer-data

Copy link
Copy Markdown
Contributor Author

Fix issue #2153

Pillow 12.1.0 has an out-of-bounds write when loading PSD images
(CVE-2026-25990); 12.2.0 contains the fix. Closes MoonshotAI#2153.
@7Sageer
7Sageer force-pushed the fix/pillow-12.2.0 branch from bd5874b to fe9da03 Compare May 12, 2026 08:12
@7Sageer

7Sageer commented May 12, 2026

Copy link
Copy Markdown
Collaborator

@codex

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. What shall we delve into next?

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@7Sageer
7Sageer force-pushed the fix/pillow-12.2.0 branch from fe9da03 to a9350df Compare May 12, 2026 08:56
@7Sageer
7Sageer merged commit 30be65b into MoonshotAI:main May 12, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Update pillow 12.1.0 -> 12.2.0

2 participants