Skip to content

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Oct 26, 2020

Bumps pillow from 7.2.0 to 8.0.1.

Release notes

Sourced from pillow's releases.

8.0.1

https://pillow.readthedocs.io/en/stable/releasenotes/8.0.1.html

8.0.0

https://pillow.readthedocs.io/en/stable/releasenotes/8.0.0.html

Changelog

Sourced from pillow's changelog.

8.0.1 (2020-10-22)

  • Update FreeType used in binary wheels to 2.10.4 to fix CVE-2020-15999. [radarhere]

  • Moved string_dimension image to pillow-depends #4993 [radarhere]

8.0.0 (2020-10-15)

  • Drop support for EOL Python 3.5 #4746, #4794 [hugovk, radarhere, nulano]

  • Drop support for PyPy3 < 7.2.0 #4964 [nulano]

  • Remove ImageCms.CmsProfile attributes deprecated since 3.2.0 #4768 [hugovk, radarhere]

  • Remove long-deprecated Image.py functions #4798 [hugovk, nulano, radarhere]

  • Add support for 16-bit precision JPEG quantization values #4918 [gofr]

  • Added reading of IFD tag type #4979 [radarhere]

  • Initialize offset memory for PyImagingPhotoPut #4806 [nqbit]

  • Fix TiffDecode comparison warnings #4756 [nulano]

  • Docs: Add dark mode #4968 [hugovk, nulano]

  • Added macOS SDK install path to library and include directories #4974 [radarhere, fxcoudert]

  • Imaging.h: prevent confusion with system #4923 [ax3l, ,radarhere]

  • Avoid using pkg_resources in PIL.features.pilinfo #4975 [nulano]

  • Add getlength and getbbox functions for TrueType fonts #4959 [nulano, radarhere, hugovk]

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually

@dependabot @github
Copy link
Author

dependabot bot commented on behalf of github Oct 26, 2020

The following labels could not be found: dependencies, backport 3.x.

@dependabot @github
Copy link
Author

dependabot bot commented on behalf of github Jan 4, 2021

Superseded by #95.

@dependabot dependabot bot closed this Jan 4, 2021
@dependabot dependabot bot deleted the dependabot/pip/pillow-8.0.1 branch January 4, 2021 11:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants