Sign in

Pillow

@pillow.fosstodon.org.ap.brid.gy
17 followers 0 following 9 posts

Pillow is the Python imaging library 🌉 bridged from ⁂ fosstodon.org/@pillow, follow @ap.brid.gy to interact

PostsRepliesMedia
Pillow @pillow.fosstodon.org.ap.brid.gy · 01/07/2026
Pillow 12.3.0 has been released! This has a number of security fixes, performance improvements and Python 3.15 beta wheels. pillow.readthedocs.io/en/stable/rel…
Pillow 12.3.0 release notes
000
Pillow @pillow.fosstodon.org.ap.brid.gy · 01/04/2026
Pillow 12.2.0 has been released! This has a bunch of security fixes, new APIs for wrapping text and converting fonts, plus performance and thread-safety improvements. pillow.readthedocs.io/en/latest/rel… #Python #Pillow #PythonPillow #release #security
12.2.0 (2026-04-01)
Security
Prevent FITS decompression bomb
When decompressing GZIP data from a FITS image, Pillow did not limit the amount of data being read, meaning that it was vulnerable to GZIP decompression bombs. This was introduced in Pillow 10.3.0.

The data being read is now limited to only the necessary amount.

Fix OOB write with invalid tile extents
Pillow 12.1.1 added improved checks for tile extents to prevent an OOB write from specially crafted PSD images in Pillow >= 10.3.0. However, these checks did not consider integer overflow. This has been corrected.

Prevent PDF parsing trailer infinite loop
When parsing a PDF, if a trailer refers to itself, or a more complex cyclic loop exists, then an infinite loop occurs. Pillow now keeps a record of which trailers it has already processed. PdfParser was added in Pillow 4.2.0.

Integer overflow when processing fonts
If a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This has been fixed.

Heap buffer overflow with nested list coordinates
Passing nested lists as coordinates to APIs that accept coordinates such as ImagePath.Path, polygon() and line() could cause a heap buffer overflow, as nested lists were recursively unpacked beyond the allocated buffer. Coordinate lists are now validated to contain exactly two numeric coordinates. This was introduced in Pillow 11.2.1.

API changes
Error when encoding an empty image
Attempting to encode an image with zero width or height would previously raise a SystemError. That has now been changed to a ValueError.

This does not add any new errors. SGI, ICNS and ICO formats are still able to save (0, 0) images.

API additions
FontFile.to_imagefont()
FontFile instances can now be directly converted to ImageFont instances:

from PIL import PcfFontFile
with open("Tests/fonts/10x20-ISO8859-1.pcf", "rb") as fp:
  pcffont = PcfFontFile.PcfFontFile(fp)
  pcffont.to_imagefont()

<PIL.ImageFont.ImageFont object at 0x10457bb80>
ImageText.Text.wrap
ImageText.Text.wrap() has been added, to wrap text to fit within a given width:

from PIL import ImageText
text = ImageText.Text("Hello World!")
text.wrap(50)
print(text.text)  # "Hello\nWorld!"
or within a certain width and height, returning a new ImageText.Text instance if the text does not fit:

text = ImageText.Text("Text does not fit within height")
print(text.wrap(50, 25).text == " within height")
print(text.text)  # "Text does\nnot fit"
or scaling, optionally with a font size limit:

text.wrap(50, 15, "shrink")
text.wrap(50, 15, ("shrink", 7))
text.wrap(58, 10, "grow")
text.wrap(50, 50, ("grow", 12))
EXIF tag FrameRate
The EXIF tag FrameRate has been added.

Other changes
Support reading JPEG2000 images with CMYK palettes
JPEG2000 images with CMYK palettes can now be read. This is the first integration of CMYK palettes into Pillow.

Lazy plugin loading
When opening or saving an image, Pillow now lazily loads only the required plugin based on the file extension, instead of importing all plugins upfront. This makes open 2.3-15.6x faster and save 2.2-9x faster for common formats.

Thread safety for free-threaded Python
Critical sections are now used to protect FreeType font objects, improving thread safety when using fonts in the free-threaded build of Python.
020
Pillow @pillow.fosstodon.org.ap.brid.gy · 11/02/2026
Pillow 12.1.1 has been released! This is a security release, addressing an issue in Pillow >= 10.3.0, so upgrade soon!
Pillow 12.1.1 release notes
011
Pillow @pillow.fosstodon.org.ap.brid.gy · 02/01/2026
Pillow 12.1.0 has been released! Welcome in the new year with new ImageGrab functionality, improved morphology support and a deprecation. Read more at pillow.readthedocs.io/en/stable/rel…
042
Pillow @pillow.fosstodon.org.ap.brid.gy · 15/10/2025
Pillow 12.0.0 is out released! 🎨 Support for Python 3.14! 🎨 Dropped EOL 3.9! 🎨 New ImageText.Text API! 🎨 Removed deprecations! 🎨 New deprecations! 📜 And more: pillow.readthedocs.io/en/stable/rel… 📜📜📜 And much more […]
fosstodon.org
Original post on fosstodon.org
022
Pillow @pillow.fosstodon.org.ap.brid.gy · 01/07/2025
Pillow 11.3.0 has been released! This release offers wheels that include AVIF support, wheels for Python 3.14 and even iOS wheels. Read more about our changes and a security fix at pillow.readthedocs.io/en/stable/rel…
Pillow 11.3.0 release notes
032
Pillow @pillow.fosstodon.org.ap.brid.gy · 12/04/2025
🐍🚀🎨 Pillow 11.2.1 has been released! What happened to 11.2.0? Two things: we added AVIF support which made the wheels much bigger, and we hit the PyPI project size limit before the release could be fully updated. 11.2.1 instead has AVIF support but needs to […] [Original post on fosstodon.org]
11.2.1 (2025-04-12)

Warning
The release of Pillow 11.2.0 was halted prematurely, due to hitting PyPI’s project size limit and concern over the size of Pillow wheels containing libavif. The PyPI limit has now been increased and Pillow 11.2.1 has been released instead, without libavif included in the wheels. To avoid confusion, the incomplete 11.2.0 release has been removed from PyPI.

Security
Undefined shift when loading compressed DDS images
When loading some compressed DDS formats, an integer was bitshifted by 24 places to generate the 32 bits of the lookup table. This was undefined behaviour, and has been present since Pillow 3.4.0.

Deprecations
Image.Image.get_child_images()
Deprecated since version 11.2.1.

Image.Image.get_child_images() has been deprecated. and will be removed in Pillow 13 (2026-10-15). It will be moved to ImageFile.ImageFile.get_child_images(). The method uses an image’s file pointer, and so child images could only be retrieved from an PIL.ImageFile.ImageFile instance.

API Changes
append_images no longer requires save_all
Previously, save_all was required to in order to use append_images. Now, save_all will default to True if append_images is not empty and the format supports saving multiple frames:

im.save("out.gif", append_images=ims)API Additions
"justify" multiline text alignment
In addition to "left", "center" and "right", multiline text can also be aligned using "justify" in ImageDraw:

from PIL import Image, ImageDraw
im = Image.new("RGB", (50, 25))
draw = ImageDraw.Draw(im)
draw.multiline_text((0, 0), "Multiline\ntext 1", align="justify")
draw.multiline_textbbox((0, 0), "Multiline\ntext 2", align="justify")

Specify window in ImageGrab on Windows

When using grab(), a specific window can be selected using the HWND:

from PIL import ImageGrab
ImageGrab.grab(window=hwnd)

Check for MozJPEG

You can check if Pillow has been built against the MozJPEG version of the libjpeg library, and what version of MozJPEG is being used:

from PIL import features
features.check_feature("mozjpeg")  # True or False
features.version_feature("mozjpeg")  # "4.1.1" for example, or None

Saving compressed DDS images

Compressed DDS images can now be saved using a pixel_format argument. DXT1, DXT3, DXT5, BC2, BC3 and BC5 are supported:

im.save("out.dds", pixel_format="DXT1")Other Changes

Arrow support
Arrow is an in-memory data exchange format that is the spiritual successor to the NumPy array interface. It provides for zero-copy access to columnar data, which in our case is Image data.

To create an image with zero-copy shared memory from an object exporting the arrow_c_array interface protocol:

from PIL import Image
import pyarrow as pa
arr = pa.array([0]*(5*5*4), type=pa.uint8())
im = Image.fromarrow(arr, 'RGBA', (5, 5))

Pillow images can also be converted to Arrow objects:

from PIL import Image
import pyarrow as pa
im = Image.open('hopper.jpg')
arr = pa.array(im)

Reading and writing AVIF images

Pillow can now read and write AVIF images when built from source with libavif 1.0.0 or later.
001
Pillow @pillow.fosstodon.org.ap.brid.gy · 02/04/2025
Quarterly release update: We "yanked" yesterday's 11.2.0 release because we hit the project size limit on PyPI before all the files could be uploaded. We've requested an increase and will upload the rest and un-yank, or create a new release later […]
fosstodon.org
Original post on fosstodon.org
001
Pillow @pillow.fosstodon.org.ap.brid.gy · 02/01/2025
Pillow 11.1.0 has been released! We're now using zlib-ng in our wheels for improved speed. pillow.readthedocs.io/en/stable/rel…
062
Reposted by Pillow
Seth Larson @sethmlarson.fosstodon.org.ap.brid.gy · 03/12/2024
I've noticed a concerning trend of "slop security reports" being sent to open source projects. Here are thoughts about what platforms, reporters, and maintainers can do to push back: #oss #opensource #security #vulnerability #vuln #cve #slop #ai #llm […]
fosstodon.org
Original post on fosstodon.org
010