Skip to content

Conversation

@Zerpet
Copy link
Member

@Zerpet Zerpet commented Jun 1, 2022

Note to reviewers: remember to look at the commits in this PR and consider if they can be squashed
Note to contributors: remember to re-generate client set if there are any API changes

Summary Of Changes

GoYaml dependency has a known CVE-2022-28948. It is fixed in versions
v3.0.0+

Go Client also has a dependency on this package. It looks like Client Go
does not use the vulnerable version.

Regenerated Client Set since we changed our dependencies.

Additional Context

Unit and integration tests are passing locally.

GoYaml dependency has a known CVE-2022-28948. It is fixed in versions
v3.0.0+

Go Client also has a dependency on this package. It looks like Client Go
does not use the vulnerable version.

Regenerated Client Set since we changed our dependencies.

Signed-off-by: Aitor Perez Cedres <[email protected]>
Copy link
Contributor

@ChunyiLyu ChunyiLyu left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

YES

@Zerpet Zerpet merged commit 319ed6a into main Jun 1, 2022
@Zerpet Zerpet deleted the fix-dependabot-alert branch June 1, 2022 14:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants