Bump pillow from 8.0.1 to 8.1.0
Created by: dependabot-preview[bot]
Bumps pillow from 8.0.1 to 8.1.0.
Release notes
Sourced from pillow's releases.
8.1.0
https://pillow.readthedocs.io/en/stable/releasenotes/8.1.0.html
Changes
- Fix TIFF OOB Write error #5175 [@radarhere]
- Fix for Buffer Read Overrun in PCX Decoding #5174 [@radarhere]
- Fix for SGI Decode buffer overrun #5173 [@radarhere]
- Fix OOB Read when saving GIF of xsize=1 #5149 [@wiredfool]
- Add support for PySide6 #5161 [@hugovk]
- Moved QApplication into one test #5167 [@radarhere]
- Use disposal settings from previous frame in APNG #5126 [@radarhere]
- Revert "skip wheels on 3.10-dev due to wheel#354" #5163 [@radarhere]
- Better _binary module use #5156 [@radarhere]
- Added exception explaining that repr_png saves to PNG #5139 [@radarhere]
- Use previous disposal method in GIF load_end #5125 [@radarhere]
- Do not catch a ValueError only to raise another #5090 [@radarhere]
- Allow putpalette to accept 1024 integers to include alpha values #5089 [@radarhere]
- Fix OOB Read when writing TIFF with custom Metadata #5148 [@wiredfool]
- Removed unused variable #5140 [@radarhere]
- Fix dereferencing of potential null pointers #5111 [@cgohlke]
- Fixed warnings assigning to "unsigned char *" from "char *" #5127 [@radarhere]
- Add append_images support for ICO #4568 [@ziplantil]
- Fixed comparison warnings #5122 [@radarhere]
- Block TIFFTAG_SUBIFD #5120 [@radarhere]
- Fix dereferencing potential null pointer #5108 [@cgohlke]
- Replaced PyErr_NoMemory with ImagingError_MemoryError #5113 [@radarhere]
- Remove duplicate code #5109 [@cgohlke]
- Moved warning to end of execution #4965 [@radarhere]
- Removed unused fromstring and tostring C methods #5026 [@radarhere]
- init() if one of the formats is unrecognised #5037 [@radarhere]
Dependencies
- Updated libtiff to 4.2.0 #5153 [@radarhere]
- Updated openjpeg to 2.4.0 #5151 [@radarhere]
- Updated harfbuzz to 2.7.4 #5138 [@radarhere]
- Updated harfbuzz to 2.7.3 #5128 [@radarhere]
- Updated libraqm to 0.7.1 #5070 [@radarhere]
- Updated libimagequant to 2.13.1 #5065 [@radarhere]
- Update FriBiDi to 1.0.10 #5064 [@nulano]
- Updated libraqm to 0.7.1 #5063 [@radarhere]
- Updated libjpeg-turbo to 2.0.6 #5044 [@radarhere]
Deprecations
Changelog
Sourced from pillow's changelog.
8.1.0 (2020-01-02)
- Fix TIFF OOB Write error. CVE-2020-35654 #5175 [wiredfool]
- Fix for Read Overflow in PCX Decoding. CVE-2020-35653 #5174 [wiredfool, radarhere]
- Fix for SGI Decode buffer overrun. CVE-2020-35655 #5173 [wiredfool, radarhere]
- Fix OOB Read when saving GIF of xsize=1 #5149 [wiredfool]
- Makefile updates #5159 [wiredfool, radarhere]
- Add support for PySide6 #5161 [hugovk]
- Use disposal settings from previous frame in APNG #5126 [radarhere]
- Added exception explaining that _repr_png saves to PNG #5139 [radarhere]
- Use previous disposal method in GIF load_end #5125 [radarhere]
- Allow putpalette to accept 1024 integers to include alpha values #5089 [radarhere]
- Fix OOB Read when writing TIFF with custom Metadata #5148 [wiredfool]
- Added append_images support for ICO #4568 [ziplantil, radarhere]
- Block TIFFTAG_SUBIFD #5120 [radarhere]
- Fixed dereferencing potential null pointers #5108, #5111 [cgohlke, radarhere]
- Deprecate FreeType 2.7 #5098 [hugovk, radarhere]
- Moved warning to end of execution #4965 [radarhere]
- Removed unused fromstring and tostring C methods #5026 [radarhere]
- init() if one of the formats is unrecognised #5037 [radarhere]
- Moved string_dimension CVE image to pillow-depends #4993 [radarhere]
- Support raw rgba8888 for DDS #4760 [qiankanglai]
Commits
-
fcc42e0
8.1.0 version bump -
a991280
Update CHANGES.rst [ci skip] -
470e48b
Merge pull request #5176 from radarhere/security -
cd316fe
Link to OSS-Fuzz [ci skip] -
2711549
Link to TideLift [ci skip] -
d88fdcd
Updated capitalisation [ci skip] -
95f99d5
Document CVE fixes [ci skip] -
c8dd1c8
Merge pull request #5175 from radarhere/tiff -
0117694
Merge pull request #5174 from radarhere/pcx -
120eea2
Merge pull request #5173 from radarhere/sgi - Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) -
@dependabot use these labels
will set the current labels as the default for future PRs for this repo and language -
@dependabot use these reviewers
will set the current reviewers as the default for future PRs for this repo and language -
@dependabot use these assignees
will set the current assignees as the default for future PRs for this repo and language -
@dependabot use this milestone
will set the current milestone as the default for future PRs for this repo and language -
@dependabot badge me
will comment on this PR with code to add a "Dependabot enabled" badge to your readme
Additionally, you can set the following in your Dependabot dashboard:
- Update frequency (including time of day and day of week)
- Pull request limits (per update run and/or open at any time)
- Out-of-range updates (receive only lockfile updates, if desired)
- Security updates (receive only security updates, if desired)