mirror of
https://github.com/django/django.git
synced 2025-10-23 21:59:11 +00:00
Bumped minimum Pillow version to 6.2.0 in test requirements.
Pillow < 6.2.0 is vulnerable to CVE-2019-16865.
This commit is contained in:
@@ -277,7 +277,7 @@ dependencies:
|
||||
* geoip2_
|
||||
* jinja2_ 2.7+
|
||||
* numpy_
|
||||
* Pillow_
|
||||
* Pillow_ 6.2.0+
|
||||
* PyYAML_
|
||||
* pytz_ (required)
|
||||
* pywatchman_
|
||||
|
||||
Reference in New Issue
Block a user