Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Oct 15, 2025

This PR contains the following updates:

Package Change Age Confidence
pillow (changelog) ==11.3.0 -> ==12.0.0 age confidence

Release Notes

python-pillow/Pillow (pillow)

v12.0.0

Compare Source


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label Oct 15, 2025
@github-actions
Copy link

github-actions bot commented Oct 15, 2025

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
pip/pillow 12.0.0 🟢 7.6
Details
CheckScoreReason
Code-Review🟢 8Found 11/13 approved changesets -- score normalized to 8
Security-Policy🟢 10security policy file detected
Maintained🟢 1030 commit(s) and 24 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
CII-Best-Practices🟢 5badge detected: Passing
Binary-Artifacts🟢 10no binaries found in the repo
License🟢 9license file detected
Signed-Releases⚠️ -1no releases found
Fuzzing🟢 10project is fuzzed
Vulnerabilities🟢 100 existing vulnerabilities detected
Packaging🟢 10packaging workflow detected
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0

Scanned Files

  • requirements.txt

@renovate renovate bot force-pushed the renovate/pillow-12.x branch 9 times, most recently from fd6e767 to 7223f02 Compare October 22, 2025 00:55
@renovate renovate bot force-pushed the renovate/pillow-12.x branch 9 times, most recently from 3078aff to 3ee145f Compare October 30, 2025 00:44
@renovate renovate bot force-pushed the renovate/pillow-12.x branch 6 times, most recently from d283973 to 5e37e80 Compare November 5, 2025 01:27
@renovate renovate bot force-pushed the renovate/pillow-12.x branch 4 times, most recently from 2a8abee to a2e69e1 Compare November 8, 2025 13:56
@renovate renovate bot force-pushed the renovate/pillow-12.x branch 10 times, most recently from b55846b to 9981210 Compare November 19, 2025 01:12
@renovate renovate bot force-pushed the renovate/pillow-12.x branch 11 times, most recently from 44ae1f3 to dc36d6e Compare November 28, 2025 00:56
@renovate renovate bot force-pushed the renovate/pillow-12.x branch 2 times, most recently from 00deba8 to 94514d1 Compare November 28, 2025 02:57
@renovate renovate bot force-pushed the renovate/pillow-12.x branch from 94514d1 to 26ed662 Compare November 28, 2025 02:59
@iwamot iwamot self-assigned this Nov 28, 2025
@iwamot
Copy link
Collaborator

iwamot commented Nov 28, 2025

Staying on Pillow <12.0.0 because strands-agents-tools 0.2.16 restricts pillow to <12.0.0.
Tracking upstream fix at: strands-agents/tools#299

@iwamot iwamot closed this Nov 28, 2025
@renovate
Copy link
Contributor Author

renovate bot commented Nov 28, 2025

Renovate Ignore Notification

Because you closed this PR without merging, Renovate will ignore this update. You will not get PRs for any future 12.x releases. But if you manually upgrade to 12.x then Renovate will re-enable minor and patch updates automatically.

If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR.

@renovate renovate bot deleted the renovate/pillow-12.x branch November 28, 2025 03:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants