bug#47259: python-pillow-simd package vulnerable to at least CVE-2021-25293

2022-03-22 Thread Maxim Cournoyer
Hi Léo, Léo Le Bouter writes: > Hello! > > pillow-simd is a fork of pillow ( > https://github.com/uploadcare/pillow-simd), it's currently still at > version 7.x and it does not seem like it backports security patches > from pillow. Thanks for the heads-up; our package is currently at 9.0.0, and

bug#47259: python-pillow-simd package vulnerable to at least CVE-2021-25293

2022-03-23 Thread Maxime Devos
Maxim Cournoyer schreef op di 22-03-2022 om 22:57 [-0400]: > Léo Le Bouter writes: > > > Hello! > > > > pillow-simd is a fork of pillow ( > > https://github.com/uploadcare/pillow-simd), it's currently still at > > version 7.x and it does not seem like it backports security patches > > from pillo

bug#47259: python-pillow-simd package vulnerable to at least CVE-2021-25293

2022-03-23 Thread Maxim Cournoyer
Hi, Maxime Devos writes: > Maxim Cournoyer schreef op di 22-03-2022 om 22:57 [-0400]: >> Léo Le Bouter writes: >> >> > Hello! >> > >> > pillow-simd is a fork of pillow ( >> > https://github.com/uploadcare/pillow-simd), it's currently still at >> > version 7.x and it does not seem like it back

bug#47259: python-pillow-simd package vulnerable to at least CVE-2021-25293

2021-03-19 Thread Léo Le Bouter via Bug reports for GNU Guix
Hello! pillow-simd is a fork of pillow ( https://github.com/uploadcare/pillow-simd), it's currently still at version 7.x and it does not seem like it backports security patches from pillow. $ ./pre-inst-env guix refresh -l python-pillow-simd No dependents other than itself: python-pillow-simd@7.1