Thursday, May 7, 2026
shippedPillow security update in llm-compressor 0.7.1.2
Recoordinate released llm-compressor 0.7.1.2 to patch a security vulnerability in the pillow dependency.
The vllm-project/llm-compressor repository received a minor version bump [1] to address a known security issue. The fix updated the pillow version to resolve the vulnerability, the only change between 0.7.1.1 and 0.7.1.2.
Sources
- v0.7.1.2 · vllm-project/llm-compressor