Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependabot reports for potential security vulnerabilities #2521

Closed
532910 opened this issue May 27, 2022 · 5 comments
Closed

Dependabot reports for potential security vulnerabilities #2521

532910 opened this issue May 27, 2022 · 5 comments

Comments

@532910
Copy link

532910 commented May 27, 2022

image

https://github.com/nspcc-dev/neo-go/security/dependabot

@roman-khimov
Copy link
Member

I know about it, but I'm not sure we have an actual problem here, because originally it's for a different version of the package we use. But it needs to be checked.

@532910
Copy link
Author

532910 commented May 27, 2022

I believe the main actual problem is in the banner itself, as github is the front page for our code.

@roman-khimov
Copy link
Member

It's not visible to outsiders.

@roman-khimov
Copy link
Member

I've just looked at the code, and it seems like it affects us. As well as go-yaml/yaml#665, so we need to move on with #2085.

@roman-khimov
Copy link
Member

Fixed by #2527.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants