Skip to content

Commit d9aa73a

Browse files
committed
fix: add an explicit constraint on Pillow to block known-vulnerable versions
1 parent 72d63ec commit d9aa73a

1 file changed

Lines changed: 3 additions & 0 deletions

File tree

pyproject.toml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,9 @@ requires-python = ">=3.11"
1818
dependencies = [
1919
"flask>=3.0,<4",
2020
"fpdf2>=2.7,<3",
21+
# fpdf2 depends on Pillow; declare a floor + cap so resolvers cannot pick
22+
# known-vulnerable Pillow releases while staying on Pillow 10.x.
23+
"pillow>=10.0.0,<11",
2124
]
2225

2326
[project.optional-dependencies]

0 commit comments

Comments
 (0)