python-pillow / python-pillow/Pillow
Release notes for 12.3.0 not updated to show CVEs
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 13.8k
- Forks
- 2.5k
- Avg merge
- 2d 8h
- Merged PRs (30d)
- 89
Description
What did you do?
Went to https://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html in a web browser.
What did you expect to happen?
Looking to see if 12.3.0 fixes CVE-2026-54058.
What actually happened?
That CVE (-54058) was not listed by CVE number, although other CVEs (-55798, -54059, -54060, etc.) were shown with links.
What are your OS, Python and Pillow versions?
N/A
It appears that the published HTML on readthedocs.io was not updated after the docs/releasenotes/12.3.0.rst file was updated on July 7.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with docs/releasenotes/12.3.0.rst and compare it with the published 12.3.0 Read the Docs page. Check how the documentation is built and published, then verify that CVE-2026-54058 appears in the rendered release notes alongside the other CVEs.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, release
- Issue type
- Documentation
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Active
- Clarity
- Clearly specified
- Newbie friendliness
- 78/100