fix: bump pillow to >=12.2.0 (CVE-2026-40192)#6073
Conversation
GHSA-whj4-6x5x-4v2j Only applies to release-0.4.x; pillow already pinned >=12.2.0 on main. Signed-off-by: Matthew F Leader <mleader@redhat.com>
✱ Stainless preview buildsThis PR will update the Edit this comment to update it. It will appear in the SDK's changelogs. ✅ llama-stack-client-openapi studio · code · diff
✅ llama-stack-client-node studio · conflict
✅ llama-stack-client-python studio · conflict
✅ llama-stack-client-go studio · conflict
This comment is auto-generated by GitHub Actions and is automatically kept up to date as you push. |
What does this PR do?
Bump
pillowto>=12.2.0in dependencies and provider registry to address CVE-2026-40192, GHSA-whj4-6x5x-4v2jOnly applies to
release-0.4.x;pillowalready pinned>=12.2.0onmain.Test Plan
No functional changes. Version floor pin only.