Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fixing CVE-2022-28948 #214

Merged
merged 1 commit into from
Jun 10, 2023
Merged

Fixing CVE-2022-28948 #214

merged 1 commit into from
Jun 10, 2023

Conversation

saranyareddy24
Copy link
Contributor

@saranyareddy24 saranyareddy24 commented Jun 10, 2023

updated gopkg.in/yaml.v3 v3.0.0-20210107192922-496545a6307b to gopkg.in/yaml.v3 v3.0.0 to resolve the CVE-2022-28948

Verified with trivy scan after the change and the CVE is no more seen.

Fixes #199

Copy link
Contributor

@eshepelyuk eshepelyuk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Plz complete DCO check.

Signed-off-by: saranyareddy24 <saranyareddipalle@yahoo.in>
Copy link
Contributor

@eshepelyuk eshepelyuk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Plz rebase and squash the PR into single commit.

@saranyareddy24
Copy link
Contributor Author

Squashed the commits to one.

@eshepelyuk eshepelyuk merged commit 9004558 into open-policy-agent:master Jun 10, 2023
2 checks passed
@eshepelyuk
Copy link
Contributor

Thanks for the contribution, will release new version now.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

CVE reported for gopkg.in/yaml.v3
2 participants