Skip to content

Bump Pillow to 12.3.0 - #567

Draft
sauravpanda wants to merge 1 commit into
mainfrom
codex/fix-pillow-cves
Draft

Bump Pillow to 12.3.0#567
sauravpanda wants to merge 1 commit into
mainfrom
codex/fix-pillow-cves

Conversation

@sauravpanda

@sauravpanda sauravpanda commented Jul 29, 2026

Copy link
Copy Markdown
Collaborator

Summary

Root cause

Browser Harness pins Pillow exactly, so downstream packages cannot select the patched 12.3.0 release through normal wheel metadata.

Validation

  • uv run --with pytest pytest tests/unit/test_helpers.py (18 passed)

Summary by cubic

Upgrade pillow to 12.3.0 to patch CVE-2026-55798, CVE-2026-59198, and CVE-2026-59203. This unblocks security updates in browser-use and workflow-use.

  • Dependencies
    • Update exact pin: pillow 12.2.0 -> 12.3.0.

Written for commit 331ad6a. Summary will update on new commits.

Review in cubic

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant