[PR #3597] [MERGED] Update pillow version to 6.2.0 #12587

Closed
opened 2025-12-29 22:22:29 +01:00 by adam · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/netbox-community/netbox/pull/3597
Author: @dgarros
Created: 10/11/2019
Status: Merged
Merged: 10/15/2019
Merged by: @jeremystretch

Base: developHead: patch-1


📝 Commits (1)

  • 4cc2972 Update pillow version to 6.2.0

📊 Changes

1 file changed (+1 additions, -1 deletions)

View changed files

📝 requirements.txt (+1 -1)

📄 Description

A new CVE just got reporter regarding Pillow, it's affecting all version prior to 6.2.0 and currently netbox requires 6.0.0
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16865

Fixes: #3611

Update Pillow version in the requirements.txt file from 6.0.0 to 6.2.0


🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/netbox-community/netbox/pull/3597 **Author:** [@dgarros](https://github.com/dgarros) **Created:** 10/11/2019 **Status:** ✅ Merged **Merged:** 10/15/2019 **Merged by:** [@jeremystretch](https://github.com/jeremystretch) **Base:** `develop` ← **Head:** `patch-1` --- ### 📝 Commits (1) - [`4cc2972`](https://github.com/netbox-community/netbox/commit/4cc29729f98afe2f4271b2ee1c0ff34c1c1e8f60) Update pillow version to 6.2.0 ### 📊 Changes **1 file changed** (+1 additions, -1 deletions) <details> <summary>View changed files</summary> 📝 `requirements.txt` (+1 -1) </details> ### 📄 Description A new CVE just got reporter regarding Pillow, it's affecting all version prior to 6.2.0 and currently netbox requires 6.0.0 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16865 ### Fixes: #3611 Update Pillow version in the requirements.txt file from 6.0.0 to 6.2.0 --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
adam added the pull-request label 2025-12-29 22:22:29 +01:00
adam closed this issue 2025-12-29 22:22:30 +01:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/netbox#12587