pillow <= 8.2.0 has a CRITICAL CVE
https://nvd.nist.gov/vuln/detail/CVE-2021-34552
Recent versions of pip-tools have different output comments. If you try a newer version you can probably avoid the churn.
Also make sure to avoid re-adding chardet (licensing complexities)
chardet
Good catch, I updated pip-tools and made sure chardet was omitted. branch dw/8394b
dw/8394b
Log in to post a comment.
Recent versions of pip-tools have different output comments. If you try a newer version you can probably avoid the churn.
Also make sure to avoid re-adding
chardet
(licensing complexities)Good catch, I updated pip-tools and made sure
chardet
was omitted. branchdw/8394b