From 98298ce7f862518b571e1919c69c37bb5d59e20d Mon Sep 17 00:00:00 2001 From: Alexandru Ardelean Date: Thu, 9 Apr 2026 08:27:43 +0300 Subject: [PATCH] python3-pillow: update to 12.2.0 Update package to 12.2.0. Security fixes: - Prevent FITS decompression bomb -- GZIP data from FITS images is now limited to prevent decompression bomb attacks - Fix OOB write with invalid tile extents -- 12.1.1 PSD tile extent checks did not account for integer overflow - Prevent PDF parsing trailer infinite loop -- cyclic trailer references in PDFs are now detected and stopped - Fix integer overflow when processing fonts with excessively large per-glyph advances - Fix heap buffer overflow with nested list coordinates -- nested lists passed to ImagePath.Path, polygon(), line() etc. are now validated to contain exactly two numeric coordinates New features: - ImageText.Text.wrap() -- new method to wrap text within a given width/height, with optional shrink/grow scaling - FontFile.to_imagefont() -- FontFile instances can now be directly converted to ImageFont instances - Support reading JPEG2000 images with CMYK palettes Performance: - Lazy plugin loading -- open is 2.3-15.6x faster, save is 2.2-9x faster for common formats Signed-off-by: Alexandru Ardelean --- lang/python/pillow/Makefile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/lang/python/pillow/Makefile b/lang/python/pillow/Makefile index d36f2bc2f9..20e9763d2c 100644 --- a/lang/python/pillow/Makefile +++ b/lang/python/pillow/Makefile @@ -7,12 +7,12 @@ include $(TOPDIR)/rules.mk PKG_NAME:=pillow -PKG_VERSION:=12.1.1 +PKG_VERSION:=12.2.0 PKG_RELEASE:=1 PYPI_NAME:=Pillow PYPI_SOURCE_NAME:=pillow -PKG_HASH:=9ad8fa5937ab05218e2b6a4cff30295ad35afd2f83ac592e68c0d871bb0fdbc4 +PKG_HASH:=a830b1a40919539d07806aa58e1b114df53ddd43213d9c8b75847eee6c0182b5 PKG_BUILD_DEPENDS:=python-setuptools/host python-pybind11/host