Skip to content

Update Pillow dependency policy - #6

Merged
soodoku merged 1 commit into
mainfrom
agent/pillow-12-3-policy
Aug 16, 2026
Merged

soodoku merged 1 commit into
mainfrom
agent/pillow-12-3-policy

Conversation

@soodoku

@soodoku soodoku commented Aug 16, 2026

Copy link
Copy Markdown
Member

What changed

  • require Pillow 12.3.0 and update only Pillow's lockfile record
  • document the repository's manual dependency-review policy
  • record the change under Unreleased

Why

The default branch used Pillow 12.2.0, which GitHub flags through Dependabot. Research releases remain fixed by their tags and lockfiles, while security patches on main are reviewed manually. Automated Dependabot update pull requests are disabled; vulnerability alerts remain enabled.

Validation

  • uv lock --check
  • uv sync --locked --dev installs Pillow 12.3.0
  • make ci: 45 tests pass; formatting and lint pass
  • make paper: derived analysis only; no collection or frame extraction rerun
  • all four analysis_data.parquet files are byte-identical to version 0.1.0
  • forced 28-page LaTeX compile succeeds and ms/ms.pdf is byte-identical to version 0.1.0
  • visual inspection confirms figures, maps, and tables are not clipped

@soodoku
soodoku marked this pull request as ready for review August 16, 2026 15:52
@soodoku
soodoku merged commit 164d405 into main Aug 16, 2026
2 checks passed
@soodoku
soodoku deleted the agent/pillow-12-3-policy branch September 3, 2026 06:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant