From 855367ba61d6f05afff85d686b68ee21677c97e8 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 11 Mar 2022 23:34:27 +0000 Subject: [PATCH] Bump pillow from 5.4.1 to 9.0.1 Bumps [pillow](https://github.com/python-pillow/Pillow) from 5.4.1 to 9.0.1. - [Release notes](https://github.com/python-pillow/Pillow/releases) - [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst) - [Commits](https://github.com/python-pillow/Pillow/compare/5.4.1...9.0.1) --- updated-dependencies: - dependency-name: pillow dependency-type: direct:production ... Signed-off-by: dependabot[bot] --- requirements.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index c2352bbc8..c2d8f80ea 100644 --- a/requirements.txt +++ b/requirements.txt @@ -118,7 +118,7 @@ paramiko==2.0.9 # rq.filter: >=2.0, <2.1 # Pillow # Note: replaces obsolete PIL # https://www.djangoproject.com/weblog/2015/jan/02/pillow-security-release/ -pillow==5.4.1 +pillow==9.0.1 # Plone # CVE-2017-5524