dependabot[bot] opened a new pull request, #39395:
URL: https://github.com/apache/beam/pull/39395

   Bumps [pillow](https://github.com/python-pillow/Pillow) from 10.2.0 to 
12.3.0.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/python-pillow/Pillow/releases";>pillow's 
releases</a>.</em></p>
   <blockquote>
   <h2>12.3.0</h2>
   <p><a 
href="https://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html";>https://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html</a></p>
   <h2>Removals</h2>
   <ul>
   <li>Remove non-image ImageCms modes <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9697";>#9697</a> 
[<a href="https://github.com/radarhere";><code>@​radarhere</code></a>]</li>
   </ul>
   <h2>Documentation</h2>
   <ul>
   <li>Add release notes for SBOM and performance improvements <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9747";>#9747</a> 
[<a href="https://github.com/radarhere";><code>@​radarhere</code></a>]</li>
   <li>Add security release notes <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9741";>#9741</a> 
[<a href="https://github.com/radarhere";><code>@​radarhere</code></a>]</li>
   <li>Add release notes for Python 3.15 beta wheels <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9696";>#9696</a> 
[<a href="https://github.com/radarhere";><code>@​radarhere</code></a>]</li>
   <li>ImageFont can also be used with ImageText <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9597";>#9597</a> 
[<a href="https://github.com/radarhere";><code>@​radarhere</code></a>]</li>
   <li>Additional guidelines for security reports <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9659";>#9659</a> 
[<a href="https://github.com/wiredfool";><code>@​wiredfool</code></a>]</li>
   <li>Fixed typo <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9636";>#9636</a> 
[<a href="https://github.com/radarhere";><code>@​radarhere</code></a>]</li>
   <li>Added CVEs to 12.2.0 release notes <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9591";>#9591</a> 
[<a href="https://github.com/radarhere";><code>@​radarhere</code></a>]</li>
   <li>Revise development support information in README <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9583";>#9583</a> 
[<a href="https://github.com/aclark4life";><code>@​aclark4life</code></a>]</li>
   <li>Add INCIDENT_RESPONSE.md <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9555";>#9555</a> 
[<a href="https://github.com/aclark4life";><code>@​aclark4life</code></a>]</li>
   <li>Add STRIDE threat model to security docs <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9562";>#9562</a> 
[<a href="https://github.com/aclark4life";><code>@​aclark4life</code></a>]</li>
   <li>Add CVEs to 12.2.0 release notes <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9556";>#9556</a> 
[<a href="https://github.com/radarhere";><code>@​radarhere</code></a>]</li>
   <li>Update README with revised security policy <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9553";>#9553</a> 
[<a href="https://github.com/radarhere";><code>@​radarhere</code></a>]</li>
   <li>Update security policy <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9552";>#9552</a> 
[<a href="https://github.com/aclark4life";><code>@​aclark4life</code></a>]</li>
   <li>Update macOS tested Python versions <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9534";>#9534</a> 
[<a href="https://github.com/radarhere";><code>@​radarhere</code></a>]</li>
   </ul>
   <h2>Dependencies</h2>
   <ul>
   <li>Update dependency harfbuzz to v14.2.1 <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9720";>#9720</a> 
[@<a href="https://github.com/apps/renovate";>renovate[bot]</a>]</li>
   <li>Update dependency mypy to v2 <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9653";>#9653</a> 
[@<a href="https://github.com/apps/renovate";>renovate[bot]</a>]</li>
   <li>Update dependency cibuildwheel to v4 <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9665";>#9665</a> 
[@<a href="https://github.com/apps/renovate";>renovate[bot]</a>]</li>
   <li>Update github-actions <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9655";>#9655</a> 
[@<a href="https://github.com/apps/renovate";>renovate[bot]</a>]</li>
   <li>Update dependency libavif to v1.4.2 <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9652";>#9652</a> 
[@<a href="https://github.com/apps/renovate";>renovate[bot]</a>]</li>
   <li>Update dependency lcms2 to v2.19.1 <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9651";>#9651</a> 
[@<a href="https://github.com/apps/renovate";>renovate[bot]</a>]</li>
   <li>Update dependency check-jsonschema to v0.37.2 <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9650";>#9650</a> 
[@<a href="https://github.com/apps/renovate";>renovate[bot]</a>]</li>
   <li>Update google/oss-fuzz digest to d872252 <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9614";>#9614</a> 
[@<a href="https://github.com/apps/renovate";>renovate[bot]</a>]</li>
   <li>Update dependency lcms2 to v2.19 <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9609";>#9609</a> 
[@<a href="https://github.com/apps/renovate";>renovate[bot]</a>]</li>
   <li>Update dependency libpng to v1.6.58 - autoclosed <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9608";>#9608</a> 
[@<a href="https://github.com/apps/renovate";>renovate[bot]</a>]</li>
   <li>Update dependency harfbuzz to v14 <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9610";>#9610</a> 
[@<a href="https://github.com/apps/renovate";>renovate[bot]</a>]</li>
   <li>Update dependency mypy to v1.20.2 <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9599";>#9599</a> 
[@<a href="https://github.com/apps/renovate";>renovate[bot]</a>]</li>
   <li>Update github-actions <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9611";>#9611</a> 
[@<a href="https://github.com/apps/renovate";>renovate[bot]</a>]</li>
   <li>Update dependency cibuildwheel to v3.4.1 <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9607";>#9607</a> 
[@<a href="https://github.com/apps/renovate";>renovate[bot]</a>]</li>
   <li>Move dependency versions to single JSON and enable Renovate <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9559";>#9559</a> 
[<a href="https://github.com/hugovk";><code>@​hugovk</code></a>]</li>
   <li>Updated raqm to 0.10.5 <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9557";>#9557</a> 
[<a href="https://github.com/radarhere";><code>@​radarhere</code></a>]</li>
   <li>Update dependency cibuildwheel to v3.4.0 <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9532";>#9532</a> 
[@<a href="https://github.com/apps/renovate";>renovate[bot]</a>]</li>
   </ul>
   <h2>Testing</h2>
   <ul>
   <li>Remove matrix.os from benchmark <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9735";>#9735</a> 
[<a href="https://github.com/radarhere";><code>@​radarhere</code></a>]</li>
   <li>Remove references to libavif patch <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9734";>#9734</a> 
[<a href="https://github.com/radarhere";><code>@​radarhere</code></a>]</li>
   <li>Add benchmark tests <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9654";>#9654</a> 
[<a href="https://github.com/akx";><code>@​akx</code></a>]</li>
   <li>Use reshape() instead of setting NumPy array shape directly <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9728";>#9728</a> 
[<a href="https://github.com/radarhere";><code>@​radarhere</code></a>]</li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst";>pillow's 
changelog</a>.</em></p>
   <blockquote>
   <h1>Changelog (Pillow)</h1>
   <h2>11.1.0 and newer</h2>
   <p>See GitHub Releases:</p>
   <ul>
   <li><a 
href="https://github.com/python-pillow/Pillow/releases";>https://github.com/python-pillow/Pillow/releases</a></li>
   </ul>
   <h2>11.0.0 (2024-10-15)</h2>
   <ul>
   <li>
   <p>Update licence to MIT-CMU <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/8460";>#8460</a>
   [hugovk]</p>
   </li>
   <li>
   <p>Conditionally define ImageCms type hint to avoid requiring core <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/8197";>#8197</a>
   [radarhere]</p>
   </li>
   <li>
   <p>Support writing LONG8 offsets in AppendingTiffWriter <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/8417";>#8417</a>
   [radarhere]</p>
   </li>
   <li>
   <p>Use ImageFile.MAXBLOCK when saving TIFF images <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/8461";>#8461</a>
   [radarhere]</p>
   </li>
   <li>
   <p>Do not close provided file handles with libtiff when saving <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/8458";>#8458</a>
   [radarhere]</p>
   </li>
   <li>
   <p>Support ImageFilter.BuiltinFilter for I;16* images <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/8438";>#8438</a>
   [radarhere]</p>
   </li>
   <li>
   <p>Use ImagingCore.ptr instead of ImagingCore.id <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/8341";>#8341</a>
   [homm, radarhere, hugovk]</p>
   </li>
   <li>
   <p>Updated EPS mode when opening images without transparency <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/8281";>#8281</a>
   [Yay295, radarhere]</p>
   </li>
   <li>
   <p>Use transparency when combining P frames from APNGs <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/8443";>#8443</a>
   [radarhere]</p>
   </li>
   <li>
   <p>Support all resampling filters when resizing I;16* images <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/8422";>#8422</a>
   [radarhere]</p>
   </li>
   <li>
   <p>Free memory on early return <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/8413";>#8413</a>
   [radarhere]</p>
   </li>
   <li>
   <p>Cast int before potentially exceeding INT_MAX <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/8402";>#8402</a>
   [radarhere]</p>
   </li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/python-pillow/Pillow/commit/bb1d8e8ab8d29048624d96e3ee53cecf7c13d13d";><code>bb1d8e8</code></a>
 12.3.0 version bump</li>
   <li><a 
href="https://github.com/python-pillow/Pillow/commit/e63fc481dc2e07e21d5403deafb8f1ed98a513af";><code>e63fc48</code></a>
 Add release notes for SBOM and performance improvements (<a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9747";>#9747</a>)</li>
   <li><a 
href="https://github.com/python-pillow/Pillow/commit/13b701bbab291eec4bc87ea17ba06c94e5fe3054";><code>13b701b</code></a>
 Add release notes for <a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9679";>#9679</a></li>
   <li><a 
href="https://github.com/python-pillow/Pillow/commit/5564ca72fcd59d040e270af5dcf17a0d7161c364";><code>5564ca7</code></a>
 List methods</li>
   <li><a 
href="https://github.com/python-pillow/Pillow/commit/a0920fd384f800b5d0ba3dd29ecdeae4f1d4043b";><code>a0920fd</code></a>
 Speed up ImageChops operations (<a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9738";>#9738</a>)</li>
   <li><a 
href="https://github.com/python-pillow/Pillow/commit/07e9a6cd5336dc6cf8cae9165cd70cdd2b3e42fc";><code>07e9a6c</code></a>
 Speed up <code>Image.filter()</code> (<a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9736";>#9736</a>)</li>
   <li><a 
href="https://github.com/python-pillow/Pillow/commit/a94578cf9649ea13e426cf7fb2b71b39ffc0dd50";><code>a94578c</code></a>
 Speed up <code>Image.getchannel()</code>, <code>Image.merge()</code>, 
<code>Image.putalpha()</code> and `Image...</li>
   <li><a 
href="https://github.com/python-pillow/Pillow/commit/53e02c43c919d149b2a154a5180079f9df18fbbb";><code>53e02c4</code></a>
 Speed up <code>Image.fill()</code>, <code>Image.linear_gradient()</code> and 
`Image.radial_gradient...</li>
   <li><a 
href="https://github.com/python-pillow/Pillow/commit/af037475be8634ba739744243164ba9e2c8346a6";><code>af03747</code></a>
 Speed up <code>Image.resample()</code> (<a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9739";>#9739</a>)</li>
   <li><a 
href="https://github.com/python-pillow/Pillow/commit/5c9ca56c3e5fba52b647809fbb0986c87e73a571";><code>5c9ca56</code></a>
 Speed up <code>alpha_composite</code>, <code>matrix</code>, 
<code>negative</code>, <code>quantize</code> (<a 
href="https://redirect.github.com/python-pillow/Pillow/issues/9740";>#9740</a>)</li>
   <li>Additional commits viewable in <a 
href="https://github.com/python-pillow/Pillow/compare/10.2.0...12.3.0";>compare 
view</a></li>
   </ul>
   </details>
   <br />
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=pillow&package-manager=pip&previous-version=10.2.0&new-version=12.3.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   You can disable automated security fix PRs for this repo from the [Security 
Alerts page](https://github.com/apache/beam/network/alerts).
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to