Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[security] Bump github.com/stretchr/testify to update gopkg.in/yaml.v3 #813

Merged
merged 1 commit into from
Aug 18, 2022

Conversation

massakam
Copy link

@massakam massakam commented Jul 25, 2022

Motivation

A vulnerability scan on this repository found a vulnerable version of gopkg.in/yaml.v3.
GHSA-hp87-p4gw-j4gq

We need to upgrade the version of github.com/stretchr/testify because it directly depends on gopkg.in/yaml.v3.
stretchr/testify#1192

Modifications

Upgraded github.com/stretchr/testify to the latest version, v1.8.0.

Verifying this change

  • Make sure that the change passes the CI checks.

@massakam massakam self-assigned this Jul 25, 2022
@nkurihar nkurihar merged commit 3d63718 into apache:master Aug 18, 2022
@massakam massakam deleted the bump-testify branch August 18, 2022 04:18
@nkurihar nkurihar added this to the v0.10.0 milestone Aug 25, 2022
@nkurihar nkurihar modified the milestones: v0.10.0, v0.9.0 Nov 15, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants