Wednesday, May 6, 2026
shippedPillow security update in llm-compressor v0.9.0.3
Recoordinate pushed a patch release to vllm-project/llm-compressor to address a security issue in the pillow dependency.
llm-compressor v0.9.0.3 shipped with an updated pillow package to fix a known security vulnerability [1]. The change was minimal and focused, updating only the affected dependency for the release.
Sources
- v0.9.0.3 · vllm-project/llm-compressor