Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

dependency: bumped Snakeyaml from 1.33 to 2.2 - CVE-2022-1471 #3869

Merged
merged 1 commit into from
Sep 18, 2023

Conversation

Coduz
Copy link
Contributor

@Coduz Coduz commented Sep 15, 2023

This PR bumps the version of Snakeyaml from 1.33 to 2.2 solving follwing CVEs:

Related Issue
None

Description of the solution adopted
Changed the version of the dependency

Screenshots
None

Any side note on the changes made
None

Signed-off-by: Alberto Codutti <alberto.codutti@eurotech.com>
@Coduz Coduz added the Dependencies PR that updates dependencies. Be on the edge! label Sep 15, 2023
@codecov
Copy link

codecov bot commented Sep 15, 2023

Codecov Report

Merging #3869 (795adaa) into develop (6ef61f8) will not change coverage.
The diff coverage is n/a.

❗ Current head 795adaa differs from pull request most recent head 15b8abc. Consider uploading reports for the commit 15b8abc to get more accurate results

Impacted file tree graph

@@            Coverage Diff             @@
##             develop    #3869   +/-   ##
==========================================
  Coverage      20.59%   20.59%           
  Complexity         6        6           
==========================================
  Files           1936     1936           
  Lines          41532    41532           
  Branches        3945     3945           
==========================================
  Hits            8552     8552           
  Misses         32583    32583           
  Partials         397      397           

@Coduz Coduz merged commit a3e45b0 into eclipse-kapua:develop Sep 18, 2023
@Coduz Coduz deleted the chng-bumpSnakeyamlTo2.2 branch September 18, 2023 09:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Dependencies PR that updates dependencies. Be on the edge!
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant