The pyyaml version specified [here](https://github.com/bokeh/bokeh/blob/master/setup.py#L91) is vulnerable to to [CVE-2017-18342](https://nvd.nist.gov/vuln/detail/CVE-2017-18342).  Can this be upgraded without issue?