Skip to content

chore: use pillow 12.1.1 for python >= 3.10#6547

Merged
M1nd3r merged 1 commit into
mainfrom
m1nd3r/bump-pillow-to-12-1-1
Mar 3, 2026
Merged

chore: use pillow 12.1.1 for python >= 3.10#6547
M1nd3r merged 1 commit into
mainfrom
m1nd3r/bump-pillow-to-12-1-1

Conversation

@M1nd3r
Copy link
Copy Markdown
Contributor

@M1nd3r M1nd3r commented Mar 3, 2026

- fix for vulnerability (OOB write) https://github.com/trezor/trezor-firmware/security/dependabot/109
- pillow is used only by `toiftool`(python CLI tool), the issue does not affect the firmware itself
- patched pillow version (12.1.1) is not compatible with python 3.9, fix affects only usage with python >= 3.10

[no changelog]
@M1nd3r M1nd3r requested a review from obrusvit as a code owner March 3, 2026 10:18
@trezor-bot trezor-bot Bot added this to Firmware Mar 3, 2026
@coderabbitai
Copy link
Copy Markdown

coderabbitai Bot commented Mar 3, 2026

Important

Review skipped

Review was skipped due to path filters

⛔ Files ignored due to path filters (1)
  • uv.lock is excluded by !**/*.lock

CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including **/dist/** will override the default block on the dist directory, by removing the pattern from both the lists.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch m1nd3r/bump-pillow-to-12-1-1

Tip

Try Coding Plans. Let us write the prompt for your AI agent so you can ship faster (with fewer bugs).
Share your feedback on Discord.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-project-automation github-project-automation Bot moved this to 🔎 Needs review in Firmware Mar 3, 2026
@M1nd3r M1nd3r requested a review from matejcik March 3, 2026 10:18
@github-actions
Copy link
Copy Markdown

github-actions Bot commented Mar 3, 2026

en main(all)

model device_test click_test persistence_test
T2T1 test(all) main(all) test(all) main(all) test(all) main(all)
T3B1 test(all) main(all) test(all) main(all) test(all) main(all)
T3T1 test(all) main(all) test(all) main(all) test(all) main(all)
T3W1 test(all) main(all) test(all) main(all) test(all) main(all)

Latest CI run: 22618478129

@M1nd3r M1nd3r merged commit bfe88d2 into main Mar 3, 2026
106 checks passed
@M1nd3r M1nd3r deleted the m1nd3r/bump-pillow-to-12-1-1 branch March 3, 2026 11:28
@github-project-automation github-project-automation Bot moved this from 🔎 Needs review to 🤝 Needs QA in Firmware Mar 3, 2026
@STew790 STew790 moved this from 🤝 Needs QA to ✅ Done (no QA) in Firmware Mar 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

3 participants