fix: CVE-2026-25990 - update Pillow to >=12.1.1#1128
fix: CVE-2026-25990 - update Pillow to >=12.1.1#1128VedantMahabaleshwarkar wants to merge 1 commit intoopendatahub-io:release-v0.15from
Conversation
- Add Pillow >=12.1.1 constraint to kserve/pyproject.toml (Out-of-bounds Write via Specially Crafted PSD Image) - Update Pillow constraint in custom_model, custom_transformer, and artexplainer to match - Regenerate poetry.lock files Signed-off-by: Vedant Mahabaleshwarkar <vmahabal@redhat.com>
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: VedantMahabaleshwarkar The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
/retest |
|
/test kserve-controller-on-pull-request branch:release-v0.15 |
|
@dchourasia: The specified target(s) for Use DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
What this PR does / why we need it:
Which issue(s) this PR fixes (optional, in
fixes #<issue number>(, fixes #<issue_number>, ...)format, will close the issue(s) when PR gets merged):Fixes https://issues.redhat.com/browse/RHOAIENG-44976, https://issues.redhat.com/browse/RHOAIENG-49465
Checklist: