Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(sec): upgrade snakeyaml to 1.31 #313

Merged
merged 1 commit into from
Sep 28, 2022
Merged

fix(sec): upgrade snakeyaml to 1.31 #313

merged 1 commit into from
Sep 28, 2022

Conversation

SxLiuYu
Copy link
Contributor

@SxLiuYu SxLiuYu commented Sep 28, 2022

Upgrade snakeyaml 1.26 to 1.31 for vulnerability fix:

@tomsun28 tomsun28 changed the base branch from master to dev September 28, 2022 12:05
Copy link
Contributor

@tomsun28 tomsun28 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍👍👍 thanks!

@tomsun28 tomsun28 added the bug Something isn't working label Sep 28, 2022
@tomsun28 tomsun28 merged commit a2ea672 into apache:dev Sep 28, 2022
@tomsun28
Copy link
Contributor

tomsun28 commented Oct 1, 2022

@all-contributors please add @SxLiuYu for bug

@allcontributors
Copy link
Contributor

@tomsun28

I've put up a pull request to add @SxLiuYu! 🎉

@tomsun28
Copy link
Contributor

tomsun28 commented Oct 1, 2022

@all-contributors please add @all-contributors for doc

@allcontributors
Copy link
Contributor

@tomsun28

I've put up a pull request to add @all-contributors! 🎉

tomsun28 added a commit that referenced this pull request Oct 2, 2022
* [hertzbeat]: update to boot 2.7.4

* [hertzbeat] update to springboot 2.7.4

* [hertzbeat] use springdoc-openapi-ui instead of springfox

* [hertzbeat] use springdoc-openapi-ui instead of springfox

* [manager] upgrade snakeyaml to 1.31 (#313)

Upgrade snakeyaml 1.26 to 1.31 for vulnerability fix:
- [CVE-2022-25857](https://www.oscs1024.com/hd/MPS-2022-5144)
- [CVE-2022-25857](https://www.oscs1024.com/hd/MPS-2022-5144)
- [CVE-2022-38751](https://www.oscs1024.com/hd/MPS-2022-56040)

* [doc] add SxLiuYu as a contributor for bug (#318)

* update README.md

* update README_CN.md

* update .all-contributorsrc

Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>

* [doc] add all-contributors as a contributor for doc (#319)

* update README.md

* update README_CN.md

* update .all-contributorsrc

Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>

* [hertzbeat]: update to boot 2.7.4

* [hertzbeat] update to springboot 2.7.4

* [hertzbeat] use springdoc-openapi-ui instead of springfox

* [hertzbeat] use springdoc-openapi-ui instead of springfox

* [manager] remove illegal reflective access operation access by GlobalExceptionHandler

* [script] update workflows

* [hertzbeat] update to springboot 2.7.4

Co-authored-by: Privauto <2289751443@qq.com>
Co-authored-by: SxLiuYu <95198625+SxLiuYu@users.noreply.github.com>
Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>
tomsun28 added a commit that referenced this pull request Jan 16, 2024
* [hertzbeat]: update to boot 2.7.4

* [hertzbeat] update to springboot 2.7.4

* [hertzbeat] use springdoc-openapi-ui instead of springfox

* [hertzbeat] use springdoc-openapi-ui instead of springfox

* [manager] upgrade snakeyaml to 1.31 (#313)

Upgrade snakeyaml 1.26 to 1.31 for vulnerability fix:
- [CVE-2022-25857](https://www.oscs1024.com/hd/MPS-2022-5144)
- [CVE-2022-25857](https://www.oscs1024.com/hd/MPS-2022-5144)
- [CVE-2022-38751](https://www.oscs1024.com/hd/MPS-2022-56040)

* [doc] add SxLiuYu as a contributor for bug (#318)

* update README.md

* update README_CN.md

* update .all-contributorsrc

Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>

* [doc] add all-contributors as a contributor for doc (#319)

* update README.md

* update README_CN.md

* update .all-contributorsrc

Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>

* [hertzbeat]: update to boot 2.7.4

* [hertzbeat] update to springboot 2.7.4

* [hertzbeat] use springdoc-openapi-ui instead of springfox

* [hertzbeat] use springdoc-openapi-ui instead of springfox

* [manager] remove illegal reflective access operation access by GlobalExceptionHandler

* [script] update workflows

* [hertzbeat] update to springboot 2.7.4

Co-authored-by: Privauto <2289751443@qq.com>
Co-authored-by: SxLiuYu <95198625+SxLiuYu@users.noreply.github.com>
Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>
tomsun28 added a commit that referenced this pull request Mar 9, 2024
* [hertzbeat]: update to boot 2.7.4

* [hertzbeat] update to springboot 2.7.4

* [hertzbeat] use springdoc-openapi-ui instead of springfox

* [hertzbeat] use springdoc-openapi-ui instead of springfox

* [manager] upgrade snakeyaml to 1.31 (#313)

Upgrade snakeyaml 1.26 to 1.31 for vulnerability fix:
- [CVE-2022-25857](https://www.oscs1024.com/hd/MPS-2022-5144)
- [CVE-2022-25857](https://www.oscs1024.com/hd/MPS-2022-5144)
- [CVE-2022-38751](https://www.oscs1024.com/hd/MPS-2022-56040)

* [doc] add SxLiuYu as a contributor for bug (#318)

* update README.md

* update README_CN.md

* update .all-contributorsrc

Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>

* [doc] add all-contributors as a contributor for doc (#319)

* update README.md

* update README_CN.md

* update .all-contributorsrc

Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>

* [hertzbeat]: update to boot 2.7.4

* [hertzbeat] update to springboot 2.7.4

* [hertzbeat] use springdoc-openapi-ui instead of springfox

* [hertzbeat] use springdoc-openapi-ui instead of springfox

* [manager] remove illegal reflective access operation access by GlobalExceptionHandler

* [script] update workflows

* [hertzbeat] update to springboot 2.7.4

Co-authored-by: Privauto <2289751443@qq.com>
Co-authored-by: SxLiuYu <95198625+SxLiuYu@users.noreply.github.com>
Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>
tomsun28 added a commit that referenced this pull request Mar 9, 2024
* [hertzbeat]: update to boot 2.7.4

* [hertzbeat] update to springboot 2.7.4

* [hertzbeat] use springdoc-openapi-ui instead of springfox

* [hertzbeat] use springdoc-openapi-ui instead of springfox

* [manager] upgrade snakeyaml to 1.31 (#313)

Upgrade snakeyaml 1.26 to 1.31 for vulnerability fix:
- [CVE-2022-25857](https://www.oscs1024.com/hd/MPS-2022-5144)
- [CVE-2022-25857](https://www.oscs1024.com/hd/MPS-2022-5144)
- [CVE-2022-38751](https://www.oscs1024.com/hd/MPS-2022-56040)

* [doc] add SxLiuYu as a contributor for bug (#318)

* update README.md

* update README_CN.md

* update .all-contributorsrc

Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>

* [doc] add all-contributors as a contributor for doc (#319)

* update README.md

* update README_CN.md

* update .all-contributorsrc

Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>

* [hertzbeat]: update to boot 2.7.4

* [hertzbeat] update to springboot 2.7.4

* [hertzbeat] use springdoc-openapi-ui instead of springfox

* [hertzbeat] use springdoc-openapi-ui instead of springfox

* [manager] remove illegal reflective access operation access by GlobalExceptionHandler

* [script] update workflows

* [hertzbeat] update to springboot 2.7.4

Co-authored-by: Privauto <2289751443@qq.com>
Co-authored-by: SxLiuYu <95198625+SxLiuYu@users.noreply.github.com>
Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>
tomsun28 pushed a commit that referenced this pull request Mar 10, 2024
Upgrade snakeyaml 1.26 to 1.31 for vulnerability fix:
- [CVE-2022-25857](https:  www.oscs1024.com hd MPS-2022-5144)
- [CVE-2022-25857](https:  www.oscs1024.com hd MPS-2022-5144)
- [CVE-2022-38751](https:  www.oscs1024.com hd MPS-2022-56040)
tomsun28 added a commit that referenced this pull request Mar 10, 2024
  [hertzbeat]: update to boot 2.7.4

  [hertzbeat] update to springboot 2.7.4

  [hertzbeat] use springdoc-openapi-ui instead of springfox

  [hertzbeat] use springdoc-openapi-ui instead of springfox

  [manager] upgrade snakeyaml to 1.31 (#313)

Upgrade snakeyaml 1.26 to 1.31 for vulnerability fix:
- [CVE-2022-25857](https:  www.oscs1024.com hd MPS-2022-5144)
- [CVE-2022-25857](https:  www.oscs1024.com hd MPS-2022-5144)
- [CVE-2022-38751](https:  www.oscs1024.com hd MPS-2022-56040)

  [doc] add SxLiuYu as a contributor for bug (#318)

  update README.md

  update README_CN.md

  update .all-contributorsrc

Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>

  [doc] add all-contributors as a contributor for doc (#319)

  update README.md

  update README_CN.md

  update .all-contributorsrc

Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>

  [hertzbeat]: update to boot 2.7.4

  [hertzbeat] update to springboot 2.7.4

  [hertzbeat] use springdoc-openapi-ui instead of springfox

  [hertzbeat] use springdoc-openapi-ui instead of springfox

  [manager] remove illegal reflective access operation access by GlobalExceptionHandler

  [script] update workflows

  [hertzbeat] update to springboot 2.7.4

Co-authored-by: Privauto <2289751443@qq.com>
Co-authored-by: SxLiuYu <95198625+SxLiuYu@users.noreply.github.com>
Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>
tomsun28 pushed a commit that referenced this pull request Mar 10, 2024
Upgrade snakeyaml 1.26 to 1.31 for vulnerability fix:
- [CVE-2022-25857](https:  www.oscs1024.com hd MPS-2022-5144)
- [CVE-2022-25857](https:  www.oscs1024.com hd MPS-2022-5144)
- [CVE-2022-38751](https:  www.oscs1024.com hd MPS-2022-56040)
tomsun28 added a commit that referenced this pull request Mar 10, 2024
  [hertzbeat]: update to boot 2.7.4

  [hertzbeat] update to springboot 2.7.4

  [hertzbeat] use springdoc-openapi-ui instead of springfox

  [hertzbeat] use springdoc-openapi-ui instead of springfox

  [manager] upgrade snakeyaml to 1.31 (#313)

Upgrade snakeyaml 1.26 to 1.31 for vulnerability fix:
- [CVE-2022-25857](https:  www.oscs1024.com hd MPS-2022-5144)
- [CVE-2022-25857](https:  www.oscs1024.com hd MPS-2022-5144)
- [CVE-2022-38751](https:  www.oscs1024.com hd MPS-2022-56040)

  [doc] add SxLiuYu as a contributor for bug (#318)

  update README.md

  update README_CN.md

  update .all-contributorsrc

Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>

  [doc] add all-contributors as a contributor for doc (#319)

  update README.md

  update README_CN.md

  update .all-contributorsrc

Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>

  [hertzbeat]: update to boot 2.7.4

  [hertzbeat] update to springboot 2.7.4

  [hertzbeat] use springdoc-openapi-ui instead of springfox

  [hertzbeat] use springdoc-openapi-ui instead of springfox

  [manager] remove illegal reflective access operation access by GlobalExceptionHandler

  [script] update workflows

  [hertzbeat] update to springboot 2.7.4

Co-authored-by: Privauto <2289751443@qq.com>
Co-authored-by: SxLiuYu <95198625+SxLiuYu@users.noreply.github.com>
Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>
tomsun28 pushed a commit that referenced this pull request Mar 11, 2024
Upgrade snakeyaml 1.26 to 1.31 for vulnerability fix:
- [CVE-2022-25857](https:  www.oscs1024.com hd MPS-2022-5144)
- [CVE-2022-25857](https:  www.oscs1024.com hd MPS-2022-5144)
- [CVE-2022-38751](https:  www.oscs1024.com hd MPS-2022-56040)
tomsun28 added a commit that referenced this pull request Mar 11, 2024
  [hertzbeat]: update to boot 2.7.4

  [hertzbeat] update to springboot 2.7.4

  [hertzbeat] use springdoc-openapi-ui instead of springfox

  [hertzbeat] use springdoc-openapi-ui instead of springfox

  [manager] upgrade snakeyaml to 1.31 (#313)

Upgrade snakeyaml 1.26 to 1.31 for vulnerability fix:
- [CVE-2022-25857](https:  www.oscs1024.com hd MPS-2022-5144)
- [CVE-2022-25857](https:  www.oscs1024.com hd MPS-2022-5144)
- [CVE-2022-38751](https:  www.oscs1024.com hd MPS-2022-56040)

  [doc] add SxLiuYu as a contributor for bug (#318)

  update README.md

  update README_CN.md

  update .all-contributorsrc

Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>

  [doc] add all-contributors as a contributor for doc (#319)

  update README.md

  update README_CN.md

  update .all-contributorsrc

Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>

  [hertzbeat]: update to boot 2.7.4

  [hertzbeat] update to springboot 2.7.4

  [hertzbeat] use springdoc-openapi-ui instead of springfox

  [hertzbeat] use springdoc-openapi-ui instead of springfox

  [manager] remove illegal reflective access operation access by GlobalExceptionHandler

  [script] update workflows

  [hertzbeat] update to springboot 2.7.4

Co-authored-by: Privauto <2289751443@qq.com>
Co-authored-by: SxLiuYu <95198625+SxLiuYu@users.noreply.github.com>
Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>
tomsun28 pushed a commit that referenced this pull request Mar 11, 2024
Upgrade snakeyaml 1.26 to 1.31 for vulnerability fix:
- [CVE-2022-25857](https:  www.oscs1024.com hd MPS-2022-5144)
- [CVE-2022-25857](https:  www.oscs1024.com hd MPS-2022-5144)
- [CVE-2022-38751](https:  www.oscs1024.com hd MPS-2022-56040)
tomsun28 added a commit that referenced this pull request Mar 11, 2024
  [hertzbeat]: update to boot 2.7.4

  [hertzbeat] update to springboot 2.7.4

  [hertzbeat] use springdoc-openapi-ui instead of springfox

  [hertzbeat] use springdoc-openapi-ui instead of springfox

  [manager] upgrade snakeyaml to 1.31 (#313)

Upgrade snakeyaml 1.26 to 1.31 for vulnerability fix:
- [CVE-2022-25857](https:  www.oscs1024.com hd MPS-2022-5144)
- [CVE-2022-25857](https:  www.oscs1024.com hd MPS-2022-5144)
- [CVE-2022-38751](https:  www.oscs1024.com hd MPS-2022-56040)

  [doc] add SxLiuYu as a contributor for bug (#318)

  update README.md

  update README_CN.md

  update .all-contributorsrc

Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>

  [doc] add all-contributors as a contributor for doc (#319)

  update README.md

  update README_CN.md

  update .all-contributorsrc

Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>

  [hertzbeat]: update to boot 2.7.4

  [hertzbeat] update to springboot 2.7.4

  [hertzbeat] use springdoc-openapi-ui instead of springfox

  [hertzbeat] use springdoc-openapi-ui instead of springfox

  [manager] remove illegal reflective access operation access by GlobalExceptionHandler

  [script] update workflows

  [hertzbeat] update to springboot 2.7.4

Co-authored-by: Privauto <2289751443@qq.com>
Co-authored-by: SxLiuYu <95198625+SxLiuYu@users.noreply.github.com>
Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>
tomsun28 pushed a commit that referenced this pull request Mar 11, 2024
Upgrade snakeyaml 1.26 to 1.31 for vulnerability fix:
- [CVE-2022-25857](https:  www.oscs1024.com hd MPS-2022-5144)
- [CVE-2022-25857](https:  www.oscs1024.com hd MPS-2022-5144)
- [CVE-2022-38751](https:  www.oscs1024.com hd MPS-2022-56040)
tomsun28 added a commit that referenced this pull request Mar 11, 2024
  [hertzbeat]: update to boot 2.7.4

  [hertzbeat] update to springboot 2.7.4

  [hertzbeat] use springdoc-openapi-ui instead of springfox

  [hertzbeat] use springdoc-openapi-ui instead of springfox

  [manager] upgrade snakeyaml to 1.31 (#313)

Upgrade snakeyaml 1.26 to 1.31 for vulnerability fix:
- [CVE-2022-25857](https:  www.oscs1024.com hd MPS-2022-5144)
- [CVE-2022-25857](https:  www.oscs1024.com hd MPS-2022-5144)
- [CVE-2022-38751](https:  www.oscs1024.com hd MPS-2022-56040)

  [doc] add SxLiuYu as a contributor for bug (#318)

  update README.md

  update README_CN.md

  update .all-contributorsrc

Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>

  [doc] add all-contributors as a contributor for doc (#319)

  update README.md

  update README_CN.md

  update .all-contributorsrc

Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>

  [hertzbeat]: update to boot 2.7.4

  [hertzbeat] update to springboot 2.7.4

  [hertzbeat] use springdoc-openapi-ui instead of springfox

  [hertzbeat] use springdoc-openapi-ui instead of springfox

  [manager] remove illegal reflective access operation access by GlobalExceptionHandler

  [script] update workflows

  [hertzbeat] update to springboot 2.7.4

Co-authored-by: Privauto <2289751443@qq.com>
Co-authored-by: SxLiuYu <95198625+SxLiuYu@users.noreply.github.com>
Co-authored-by: allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants