From 6f90c12f324b5d50934f868f3db82c813e5b79ea Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 13 Jan 2022 00:57:08 +0000 Subject: [PATCH] Bump pillow from 5.4.1 to 9.0.0 Bumps [pillow](https://github.com/python-pillow/Pillow) from 5.4.1 to 9.0.0. - [Release notes](https://github.com/python-pillow/Pillow/releases) - [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst) - [Commits](https://github.com/python-pillow/Pillow/compare/5.4.1...9.0.0) --- updated-dependencies: - dependency-name: pillow dependency-type: direct:production ... Signed-off-by: dependabot[bot] --- requirements.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index c2352bbc8..1caad5528 100644 --- a/requirements.txt +++ b/requirements.txt @@ -118,7 +118,7 @@ paramiko==2.0.9 # rq.filter: >=2.0, <2.1 # Pillow # Note: replaces obsolete PIL # https://www.djangoproject.com/weblog/2015/jan/02/pillow-security-release/ -pillow==5.4.1 +pillow==9.0.0 # Plone # CVE-2017-5524