A new CVE just got reporter regarding Pillow http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16865 it's affecting all version prior to 6.2.0
@@ -16,7 +16,7 @@ graphviz==0.10.1
Jinja2==2.10.1
Markdown==2.6.11
netaddr==0.7.19
-Pillow==6.0.0
+Pillow==6.2.0
psycopg2-binary==2.8.3
py-gfm==0.1.4
pycryptodome==3.8.2