Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(snakeyaml): cve-2022-1471 upgrade #7795

Merged
merged 1 commit into from
Apr 11, 2023
Merged

fix(snakeyaml): cve-2022-1471 upgrade #7795

merged 1 commit into from
Apr 11, 2023

Conversation

meyerkev
Copy link
Contributor

We have to update Snakeyaml to use Snakeyaml 2.0 instead of 1.33

Context: https://www.veracode.com/blog/research/resolving-cve-2022-1471-snakeyaml-20-release-0

Checklist

  • The PR conforms to DataHub's Contributing Guideline (particularly Commit Message Format)
  • Links to related issues (if applicable)
  • Tests for the changes have been added/updated (if applicable)
  • Docs related to the changes have been added/updated (if applicable). If a new feature has been added a Usage Guide has been added for the same.
  • For any breaking change/potential downtime/deprecation/big changes an entry has been made in Updating DataHub

@github-actions github-actions bot added the devops PR or Issue related to DataHub backend & deployment label Apr 11, 2023
@david-leifker david-leifker merged commit 97027fe into master Apr 11, 2023
@david-leifker david-leifker deleted the snakeyaml2 branch April 11, 2023 20:17
yoonhyejin pushed a commit that referenced this pull request Apr 19, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
devops PR or Issue related to DataHub backend & deployment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants