Skip to content

Bump gopkg.in/yaml.v3 to 3.0.0#1190

Closed
edigaryev wants to merge 1 commit into
stretchr:masterfrom
edigaryev:update-yaml-v3
Closed

Bump gopkg.in/yaml.v3 to 3.0.0#1190
edigaryev wants to merge 1 commit into
stretchr:masterfrom
edigaryev:update-yaml-v3

Conversation

@edigaryev
Copy link
Copy Markdown

@edigaryev edigaryev commented May 26, 2022

To fix CVE-2022-28948.

@mkumatag
Copy link
Copy Markdown

Looking forward to see this patch merged and a new release.

@ingwarsw
Copy link
Copy Markdown
Contributor

I created the same because I didnt saw this one..
But I upgraded to 3.0.1 to fix one more issue..

See #1192

@baywet
Copy link
Copy Markdown

baywet commented May 27, 2022

Hello everyone! 👋
Can we get somebody from @stretchr to review this one or the 3.0.1 one, merge, and release please?
CC @matryer @muhqu @ernesto-jimenez @boyan-soubachov

Thanks a lot!

@boyan-soubachov
Copy link
Copy Markdown
Collaborator

This was just fixed in another PR, thank you for your contribution :)

@edigaryev edigaryev deleted the update-yaml-v3 branch June 6, 2022 12:28
@dolmen dolmen added YAML About YAML and dependency dependencies Pull requests that update a dependency file labels Mar 19, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file YAML About YAML and dependency

Projects

None yet

Development

Successfully merging this pull request may close these issues.

v3: panic "attempted to parse unknown event (please report): none"

9 participants