Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update pyyaml to latest beta version to fix security warning #23

Merged
merged 3 commits into from Apr 9, 2019

Conversation

jbedorf
Copy link
Member

@jbedorf jbedorf commented Jan 11, 2019

@jbedorf jbedorf requested a review from MrFlynn January 11, 2019 15:32
@MrFlynn
Copy link
Contributor

MrFlynn commented Jan 11, 2019

We're only using the safe_load() method, so we're not vulnerable. Not sure if we should upgrade to a beta package to fix an issue we're not vulnerable to.

@jbedorf
Copy link
Member Author

jbedorf commented Jan 14, 2019

Sure. Let's hold this open as a reminder until they bring out the official release.

@MrFlynn
Copy link
Contributor

MrFlynn commented Apr 8, 2019

@jbedorf I bumped the pyyaml version to the latest release. This fixes the CVE referenced in this issue.

@jbedorf jbedorf merged commit cd566f8 into master Apr 9, 2019
@jbedorf jbedorf deleted the dep_update branch April 9, 2019 04:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants