Repository navigation
Conversation
|
Hi there @aclark4life! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
There was a problem hiding this comment.
🟢 Approval recommended
The advisory remains valid JSON, and the added commit correctly fixes the vulnerability and is included in the listed patched release.
0 open findings
What changed in this PR
Updates the Pillow vulnerability advisory with current severity metadata and the upstream fix reference.
Changes:
- Removes the CVSS v3 severity entry.
- Adds the verified fixing commit included in Pillow 12.2.0.
| File | Description |
|---|---|
GHSA-5xmw-vc9v-4wf2.json |
Updates severity metadata and references the upstream fix. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Updates
Comments
Adds the upstream fix commit for this vulnerability.
The commit "Reject non-numeric elements inside list coords (#9526)" validates coordinate lists to contain exactly two numeric coordinates and is included in 12.2.0, the patched version already listed by this advisory.