Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
security: bump pillow to 10.2 to fix CVE-2022-22817 (#400)
Not a real problme since it's just a test dependency. Still here comes the fix for https://github.com/Guts/qgis-deployment-cli/security/dependabot/2 > Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
- Loading branch information