-
Notifications
You must be signed in to change notification settings - Fork 773
fix CVE-2021-23437 in Pillow v7 and v8 + update to Pillow v8.3.2 in easyconfigs using a 2021b toolchain #14765
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix CVE-2021-23437 in Pillow v7 and v8 + update to Pillow v8.3.2 in easyconfigs using a 2021b toolchain #14765
Conversation
This comment has been minimized.
This comment has been minimized.
|
@boegelbot: please test @ generoso |
|
@lexming: Request for testing this PR well received on login1 PR test command '
Test results coming soon (I hope)... Details- notification for comment with ID 1015693424 processed Message to humans: this is just bookkeeping information for me, |
|
Test report by @boegelbot |
|
Test report by @SebastianAchilles |
boegel
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
lgtm
|
Test report by @SebastianAchilles |
boegel
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
lgtm
|
Test report by @boegel |
|
Test report by @lexming |
|
Going in, thanks @lexming! |
(created using
eb --new-pr)Fix for CVE-2021-23437 for recent versions of Pillow.
The fix landed upstream in version 8.3.2, therefore I propose to upgrade the version of Pillow in
GCCcore/11.2.0from 8.3.1 to 8.3.2.For older toolchains we can backport the fix. This PR patches all Pillow easyconfigs since v7.0