You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
@Sher-Chowdhury To make sure this is explicitly clear, the v2 version of go-yaml is NOT affected, only the v3 version (and there is a patch to fix that vulnerability). The way I read your last sentence, it appears to me you're saying the opposite and I wanted to insure nobody else read it that way.
This relates to:
controller-runtime/go.mod
Line 26 in 196828e
As per https://www.mend.io/vulnerability-database/CVE-2022-28948, would it be possible to upgrade this yaml package to v3.0.0?
Note that this CVE incorrectly relates to v3 when it should be about v2. See here: go-yaml/yaml#666 (comment)
The text was updated successfully, but these errors were encountered: