Commit bfe88d2
committed
chore: use pillow 12.1.1 for python >= 3.10
- fix for vulnerability (OOB write) https://github.com/trezor/trezor-firmware/security/dependabot/109
- pillow is used only by `toiftool`(python CLI tool), the issue does not affect the firmware itself
- patched pillow version (12.1.1) is not compatible with python 3.9, fix affects only usage with python >= 3.10
[no changelog]1 parent dd66ef6 commit bfe88d2
1 file changed
Lines changed: 111 additions & 3 deletions
0 commit comments