Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update PyYAML to 5.3.1 #6276

Merged
merged 2 commits into from
Apr 7, 2020
Merged

Update PyYAML to 5.3.1 #6276

merged 2 commits into from
Apr 7, 2020

Conversation

FlorianVeaux
Copy link
Member

This PR updates the PyYAML dependency from 5.3.0 to 5.3.1 to include a patch for CVE-2020-1747

This CVE allows arbitrary code execution when using the full_load method but because the Datadog Agent loads yaml safely the impact is minimal. For more details: #3089

As documented here, the CVE patch is the only change between those two PyYAML versions.

@mgarabed mgarabed merged commit 6ab8285 into master Apr 7, 2020
@mgarabed mgarabed deleted the florian/update_pyyaml branch April 7, 2020 14:10
mgarabed pushed a commit that referenced this pull request Apr 7, 2020
* Update PyYAML to 5.3.1

* Freeze deps
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants