Skip to content

Conversation

@haitaohuang
Copy link

Upgrade github.com/stretchr/testify from v1.7.0 to v1.11.1, and upgrade gopkg.in/yaml.v3 to v3.0.1

This fixes CVE-2022-28948 in yaml v3.0.0

Upgrade github.com/stretchr/testify from v1.7.0 to v1.11.1,
and upgrade gopkg.in/yaml.v3 to v3.0.1

This fixes CVE-2022-28948 in yaml v3.0.0

Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
@lum1n0us lum1n0us added the bug-fix Determine if this PR addresses a bug. It will be used by scripts to classify PRs. label Jan 23, 2026
@lum1n0us
Copy link
Contributor

Usually, we don't post the patch for a security issue publicly. However, in this specific case, the targeted security advisory is not going to be accepted as a security issue because language bindings are not tier A support features and they are all experimental. Therefore, we will continue with the process.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug-fix Determine if this PR addresses a bug. It will be used by scripts to classify PRs.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants