Commit 599f89d
Update SnakeYAML-Engine to 3.0.1
There are two CVEs in Guava, which is a test-scoped dependency of
this library. Guava is not shipped with the library so these CVEs
do not affect users, but the dependency may trigger security tools.
We update to avoid this false positive.
https://www.cve.org/CVERecord?id=CVE-2023-2976
https://www.cve.org/CVERecord?id=CVE-2020-8908
Fixes #7801 parent 9daae73 commit 599f89d
1 file changed
+1
-1
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
8 | | - | |
| 8 | + | |
9 | 9 | | |
10 | 10 | | |
0 commit comments