Skip to content

fix(python-fastapi): bump pillow and python-dotenv for security advisories#108

Merged
cbullinger merged 1 commit intomainfrom
security/bump-pillow-dotenv-cve-2026
May 8, 2026
Merged

fix(python-fastapi): bump pillow and python-dotenv for security advisories#108
cbullinger merged 1 commit intomainfrom
security/bump-pillow-dotenv-cve-2026

Conversation

@cbullinger
Copy link
Copy Markdown
Collaborator

Summary

Bumps direct and constrained dependencies in mflix/server/python-fastapi to patched versions reported by Dependabot.

Changes

  • pillow 12.1.112.2.0 (constraints in requirements.in, pin in requirements.txt)
  • python-dotenv 1.1.11.2.2

Security (Dependabot)

Alert Package Severity Advisory
#51 pillow High GHSA-pwv6-vv43-88gr (CVE-2026-42311)
#50 pillow Medium GHSA-r73j-pqj5-w3x7 (CVE-2026-42310)
#49 pillow Medium GHSA-wjx4-4jcj-g98j (CVE-2026-42308)
#48 pillow Medium GHSA-5xmw-vc9v-4wf2 (CVE-2026-42309)
#47 python-dotenv Medium GHSA-mf9w-mj56-hr94 (CVE-2026-28684)

Test plan

  • requirements.txt pins match patched versions from advisories
  • CI / optional: pip install -r mflix/server/python-fastapi/requirements.txt in a clean environment

Made with Cursor

…ories

- pillow 12.2.0 (CVE-2026-42308 through CVE-2026-42311, GHSA-5xmw-vc9v-4wf2, etc.)
- python-dotenv 1.2.2 (CVE-2026-28684, GHSA-mf9w-mj56-hr94)

Addresses Dependabot alerts #47-51 on mongodb/docs-sample-apps.

Co-authored-by: Cursor <cursoragent@cursor.com>
Copy link
Copy Markdown
Collaborator

@dacharyc dacharyc left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM - thanks for adding these fixups! ✅

@cbullinger cbullinger merged commit 94580cf into main May 8, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants