mirror of
https://github.com/snapotter-hq/SnapOtter.git
synced 2026-08-03 07:46:42 +02:00
Pillow 12.x conflicts with pinned numpy 1.26.4, rembg, realesrgan, and mediapipe. Revert to working 11.1.0 pins and ignore the CVEs in pip-audit instead — they require a coordinated major version upgrade across the entire ML stack (Pillow, numpy, torch, basicsr). Ignored CVEs: - CVE-2024-27763 (basicsr, no fix available) - CVE-2026-40086 (rembg, fix needs Pillow 12) - CVE-2026-25990 (Pillow, fix is 12.1.1) - CVE-2026-40192 (Pillow, fix is 12.2.0)