Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jan 13, 2022

Bumps pillow from 8.4.0 to 9.0.0.

Release notes

Sourced from pillow's releases.

9.0.0

https://pillow.readthedocs.io/en/stable/releasenotes/9.0.0.html

Changes

... (truncated)

Changelog

Sourced from pillow's changelog.

9.0.0 (2022-01-02)

  • Restrict builtins for ImageMath.eval(). CVE-2022-22817 #5923 [radarhere]

  • Ensure JpegImagePlugin stops at the end of a truncated file #5921 [radarhere]

  • Fixed ImagePath.Path array handling. CVE-2022-22815, CVE-2022-22816 #5920 [radarhere]

  • Remove consecutive duplicate tiles that only differ by their offset #5919 [radarhere]

  • Improved I;16 operations on big endian #5901 [radarhere]

  • Limit quantized palette to number of colors #5879 [radarhere]

  • Fixed palette index for zeroed color in FASTOCTREE quantize #5869 [radarhere]

  • When saving RGBA to GIF, make use of first transparent palette entry #5859 [radarhere]

  • Pass SAMPLEFORMAT to libtiff #5848 [radarhere]

  • Added rounding when converting P and PA #5824 [radarhere]

  • Improved putdata() documentation and data handling #5910 [radarhere]

  • Exclude carriage return in PDF regex to help prevent ReDoS #5912 [hugovk]

  • Fixed freeing pointer in ImageDraw.Outline.transform #5909 [radarhere]

  • Added ImageShow support for xdg-open #5897 [m-shinder, radarhere]

  • Support 16-bit grayscale ImageQt conversion #5856 [cmbruns, radarhere]

  • Convert subsequent GIF frames to RGB or RGBA #5857 [radarhere]

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [pillow](https://github.com/python-pillow/Pillow) from 8.4.0 to 9.0.0.
- [Release notes](https://github.com/python-pillow/Pillow/releases)
- [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst)
- [Commits](python-pillow/Pillow@8.4.0...9.0.0)

---
updated-dependencies:
- dependency-name: pillow
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Jan 13, 2022
@sylvchev sylvchev merged commit b5451c4 into develop Jan 21, 2022
@dependabot dependabot bot deleted the dependabot/pip/pillow-9.0.0 branch January 21, 2022 09:55
sylvchev pushed a commit that referenced this pull request Feb 22, 2022
* Set download dir test and example (#249)

* Update to dataset_search call in FilterBank Motor Imagery

* Removing completed #fixme

* Removing total_classes argument from dataset_search call in FilterBank MI

This was earlier deprecated in 55f77ae

* set_download_dir test and example

* adding pre-commit modifications

* Update whats_new.rst

* Update examples/changing_download_directory.py

Co-authored-by: Sylvain Chevallier <[email protected]>

* Update examples/changing_download_directory.py

Co-authored-by: Sylvain Chevallier <[email protected]>

* Bump pillow from 8.4.0 to 9.0.0 (#253)

Bumps [pillow](https://github.com/python-pillow/Pillow) from 8.4.0 to 9.0.0.
- [Release notes](https://github.com/python-pillow/Pillow/releases)
- [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst)
- [Commits](python-pillow/Pillow@8.4.0...9.0.0)

---
updated-dependencies:
- dependency-name: pillow
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Fix Schirrmeister2017 error (#255)

* correct event loading error, renaming session and runs

* add whats new

* Removing dependency of Physionet MI download on mne method (#257)

* Update physionet_mi.py

* consistency of runs numbering

* Update whats_new.rst

* f-string edits

Co-authored-by: Sylvain Chevallier <[email protected]>

* f-string edits

Co-authored-by: Sylvain Chevallier <[email protected]>

Co-authored-by: Sylvain Chevallier <[email protected]>

* Correct MAMEM issues (#256)

* switch mamem session to runs, use predictable names

* update docstring in evaluation, for building documentation

* update Lee2017 docstring for correct documentation.

* update whats new

* switch SSVEP example to within session

* correct typo and rebase

* correct typos on examples

* Progress bars (#258)

* Progress bars for downloads using pooch functionality

* Rectification of f-string in PhysionetMI

* Evaluations subject level progress bar

CV test subject level in the case of CrossSubjectEvaluation

* Update poetry.lock

* Update pyproject.toml

* dependencies

* Apply suggestions from code review (mne.utils to tqdm direct)

Co-authored-by: Sylvain Chevallier <[email protected]>

* Update poetry.lock

* tqdm arg

* Update whats_new.rst

* Update mistune dep

Co-authored-by: Sylvain Chevallier <[email protected]>

* fix doc url in readme (#262)

* fix doc url in readme

* correct links in the docs

* Schirrmeister2017 High-Gamma Dataset from EDF (#265)

* loading Schirrmeister2017 High-Gamma Dataset from EDF

* remove commented import of requests module

* rename to session_0

* added 13 + 12 subjects speller datasets by huebner (#260)

* added 13 + 12 subjects speller datasets by huebner

* clean up legacy run splitting code

* added use_blocks_as_sessions parameter for data

Co-authored-by: Sylvain Chevallier <[email protected]>

* added Spot Auditory oddball dataset (#266)

* added Spot Auditory oddball dataset

* replaced usage of deprecated dl.data_path

Co-authored-by: Sylvain Chevallier <[email protected]>

* Visualize all ERP datasets (#261)

* Visualize all ERP datasets

* * use paradigm.datasets instead of manual list

* more verbose sanity check script

* fix epo data leak + remove title bf

* moved data visualization

added disclaimer regarding data size

Co-authored-by: Sylvain Chevallier <[email protected]>

* update to v0.4.5 (#269)

* update to v0.4.5

* update poetry and requirements

* correct pre-commit error and add code coverage (#271)

Co-authored-by: Divyesh Narayanan <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: robintibor <[email protected]>
Co-authored-by: Jan Sosulski <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants