Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade PyYAML #9902

Merged
merged 1 commit into from Jan 5, 2019
Merged

Upgrade PyYAML #9902

merged 1 commit into from Jan 5, 2019

Conversation

ycombinator
Copy link
Contributor

@ycombinator ycombinator merged commit 079807e into elastic:master Jan 5, 2019
ycombinator added a commit to ycombinator/beats that referenced this pull request Jan 5, 2019
ycombinator added a commit that referenced this pull request Jan 6, 2019
Cherry-pick of PR #9902 to 6.x branch. Original message: 

Addresses https://nvd.nist.gov/vuln/detail/CVE-2017-18342.
@urso
Copy link

urso commented Jan 7, 2019

I noticed some version conflicts when calling make update:

docker-compose 1.23.1 has requirement PyYAML<4,>=3.10, but you'll have pyyaml 4.2b1 which is incompatible

PyYAML issues for Reference:

There is no new docker-compose release using the pyyaml beta build yet.

It seems there is no official pyyaml release with the fix, but luckily CI didn't fail.

@ycombinator
Copy link
Contributor Author

Related issue on docker-compose GH project: docker/compose#6441

@fholzer
Copy link
Contributor

fholzer commented Jul 27, 2019

@ycombinator docker-compose 1.24.0, which supports pyyaml 4 has been released

@jmlrt jmlrt mentioned this pull request Aug 2, 2019
@ycombinator ycombinator deleted the pyyaml-upgrade branch December 25, 2019 11:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants