From 4a9dba1a2368ccca6cc2ff110e34a1cc8141b68d Mon Sep 17 00:00:00 2001 From: nelsonduarte Date: Tue, 28 Jul 2026 13:58:14 +0100 Subject: [PATCH 1/2] security(deps): bump pillow floor to 12.3.0 and update vulnerable flatpak pins Shipped artefacts (Windows/MSIX/Snap) are clean because requirements.txt resolves the >= floors to patched versions, but two gaps remained: - requirements.txt had pillow>=12.1.1, whose lower bound still permitted the vulnerable 12.1.1 (26 CVEs in image decoders). Raise it to >=12.3.0 and bump pymupdf>=1.27.2.3 -> >=1.28.0 for hygiene. - The dormant flatpak/ pinned vulnerable versions: python-modules.yml (the file flatpak-builder actually consumes) pinned pypdf 6.10.0 (17 CVEs, several in the untrusted-input PDF parser) and pillow 12.1.1, and diverged from requirements-pinned.txt (pyside6/shiboken6 6.10.2 vs 6.11.1). Regenerated with req2flatpak against the updated pinned file (target 312-x86_64); all wheel URLs/sha256 are real and verified against PyPI. Regenerate flatpak/requirements-pinned.txt: pillow 12.2.0 -> 12.3.0, pymupdf 1.27.2.3 -> 1.28.0 (pypdf already 6.14.2), keeping it coherent with the regenerated python-modules.yml. Co-Authored-By: Claude Opus 4.8 --- flatpak/python-modules.yml | 24 ++++++++++++------------ flatpak/requirements-pinned.txt | 4 ++-- requirements.txt | 4 ++-- 3 files changed, 16 insertions(+), 16 deletions(-) diff --git a/flatpak/python-modules.yml b/flatpak/python-modules.yml index 96443d3..e44de13 100644 --- a/flatpak/python-modules.yml +++ b/flatpak/python-modules.yml @@ -7,23 +7,23 @@ build-commands: pillow pymupdf pytesseract python-docx sources: - type: file - url: https://files.pythonhosted.org/packages/35/d3/ab5cd2fac3d34469c7376e0cd18eec92905dbe44748c70bda7699a2a7206/pyside6-6.10.2-cp39-abi3-manylinux_2_34_x86_64.whl - sha256: 1b89ce8558d4b4f35b85bff1db90d680912e4d3ce9e79ff804d6fef1d1a151ef + url: https://files.pythonhosted.org/packages/d8/de/af89d71410c83b10654d86ff9aff2a4f87c30163658f1cc145242e222526/pyside6-6.11.1-cp310-abi3-manylinux_2_34_x86_64.whl + sha256: b1fc521ba2bb5109425ab8add06bddbdd524abcad06cfa012cc39a22a189feb2 only-arches: - x86_64 - type: file - url: https://files.pythonhosted.org/packages/ff/79/6df7b2ee763d619cda2fb4fea498e5f79d984dae304d45a8999b80d6cf5c/pillow-12.1.1-cp312-cp312-manylinux_2_27_x86_64.manylinux_2_28_x86_64.whl - sha256: 7aac39bcf8d4770d089588a2e1dd111cbaa42df5a94be3114222057d68336bd0 + url: https://files.pythonhosted.org/packages/84/21/a35af28dcc61f37ed850a2d64c65c701321dfbf25085e469d5559360cbbf/pillow-12.3.0-cp312-cp312-manylinux_2_27_x86_64.manylinux_2_28_x86_64.whl + sha256: 78cb2c6865a35ab8ff8b75fd122f6033b92a62c82801110e48ddd6c936a45d91 only-arches: - x86_64 - type: file - url: https://files.pythonhosted.org/packages/ab/56/c6c16fa2dcfe2476ec28a9aaaca773dc35c593699e81e573211c91442770/pymupdf-1.27.2-cp310-abi3-manylinux_2_28_x86_64.whl - sha256: 917f4dd52daea504d5c60e1430c17d637b5014a43e66d068b4b356effe087dba + url: https://files.pythonhosted.org/packages/58/69/5d12c9f1f2d76f28383d6110a069c79fbfced5a4f97bb1ee6e8354f52bb7/pymupdf-1.28.0-cp310-abi3-manylinux_2_28_x86_64.whl + sha256: 44f0973f5e5edbaec95bc34b64e71d1959d4ee90b1328de1b4f4f5b4fa78673f only-arches: - x86_64 - type: file - url: https://files.pythonhosted.org/packages/55/f2/7ebe366f633f30a6ad105f650f44f24f98cb1335c4157d21ae47138b3482/pypdf-6.10.0-py3-none-any.whl - sha256: 90005e959e1596c6e6c84c8b0ad383285b3e17011751cedd17f2ce8fcdfc86de + url: https://files.pythonhosted.org/packages/49/e6/136aa8993a2ae7214e0b0ef2edaa0d2e08d1d4e4982635b08a835ff31ec8/pypdf-6.14.2-py3-none-any.whl + sha256: 3f07891af76dc002657e04993ab9b4de81de29f9013b9761d0b7968bff12e946 - type: file url: https://files.pythonhosted.org/packages/7a/33/8312d7ce74670c9d39a532b2c246a853861120486be9443eebf048043637/pytesseract-0.3.13-py3-none-any.whl sha256: 7a99c6c2ac598360693d83a416e36e0b33a67638bb9d77fdcac094a3589d4b34 @@ -31,10 +31,10 @@ sources: url: https://files.pythonhosted.org/packages/d0/00/1e03a4989fa5795da308cd774f05b704ace555a70f9bf9d3be057b680bcf/python_docx-1.2.0-py3-none-any.whl sha256: 3fd478f3250fbbbfd3b94fe1e985955737c145627498896a8a6bf81f4baf66c7 - type: file - url: https://files.pythonhosted.org/packages/11/ef/b7c8c38d1717e2fcb777678ed11568b31062e34550e23297cc32e9e1105e/qtawesome-1.4.1-py3-none-any.whl - sha256: 6a45f0ec214e0cd7c9c867772ec596799dcd5fae00a4b17717ff0d95d2e3fb64 + url: https://files.pythonhosted.org/packages/25/b1/da1d826ccc9258674b26dd0abcbbb1c55cab06e7fbf2697518b67edc79fc/qtawesome-1.4.2-py3-none-any.whl + sha256: dbf08524428fa2df73918ce362153254cd44f089380576d84bfaad8f40eece45 - type: file - url: https://files.pythonhosted.org/packages/52/88/292e0576489c46624ab419ee284ac5a59ae10e2eb34a58b6abca51dfd290/shiboken6-6.10.2-cp39-abi3-manylinux_2_34_x86_64.whl - sha256: ace0790032d9cb0adda644b94ee28d59410180d9773643bb6cf8438c361987ad + url: https://files.pythonhosted.org/packages/c7/9b/e0355d8897b5c150770f1d95718aad17d432fcc9c035c04f3f58427d4693/shiboken6-6.11.1-cp310-abi3-manylinux_2_34_x86_64.whl + sha256: 9a8bccfafc8805254cabcfa1edfaf55cd52889f4998c91ad0d9a4433fb1bcdbe only-arches: - x86_64 diff --git a/flatpak/requirements-pinned.txt b/flatpak/requirements-pinned.txt index a6d90d6..b7670dc 100644 --- a/flatpak/requirements-pinned.txt +++ b/flatpak/requirements-pinned.txt @@ -2,7 +2,7 @@ PySide6==6.11.1 shiboken6==6.11.1 pypdf==6.14.2 qtawesome==1.4.2 -pillow==12.2.0 -pymupdf==1.27.2.3 +pillow==12.3.0 +pymupdf==1.28.0 pytesseract==0.3.13 python-docx==1.2.0 diff --git a/requirements.txt b/requirements.txt index c1fd3ca..e3c7a50 100644 --- a/requirements.txt +++ b/requirements.txt @@ -4,8 +4,8 @@ pypdf>=6.14.2 # providers fixed in 48.0.1. cryptography>=49.0.0 qtawesome>=1.4.1 -pillow>=12.1.1 -pymupdf>=1.27.2.3 +pillow>=12.3.0 +pymupdf>=1.28.0 pytesseract>=0.3.13 python-docx>=1.2.0 python-pptx>=1.0.2 From 8e76f83ec113ead1a3d1e987136cacc5e737ad5d Mon Sep 17 00:00:00 2001 From: nelsonduarte Date: Tue, 28 Jul 2026 14:37:06 +0100 Subject: [PATCH 2/2] security(deps): align qtawesome floor to 1.4.2 Bump the qtawesome lower bound in requirements.txt from >=1.4.1 to >=1.4.2 to match the pinned flatpak manifests (requirements-pinned.txt and python-modules.yml already use 1.4.2, the current PyPI latest). Resolves the security-deps floor-drift report. Co-Authored-By: Claude Opus 4.8 --- requirements.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index e3c7a50..256c5d6 100644 --- a/requirements.txt +++ b/requirements.txt @@ -3,7 +3,7 @@ pypdf>=6.14.2 # GHSA-537c-gmf6-5ccf: signature verification bypass in legacy OpenSSL # providers fixed in 48.0.1. cryptography>=49.0.0 -qtawesome>=1.4.1 +qtawesome>=1.4.2 pillow>=12.3.0 pymupdf>=1.28.0 pytesseract>=0.3.13