Giter Site home page Giter Site logo

Comments (10)

ucjonathan avatar ucjonathan commented on August 22, 2024 1

Come on. It's been six more months. Just release an update so all the Maven dependencies can be updated to bring in the version of SnakeYAML that doesn't flag a CVE. It doesn't matter if you think it's a real or imaginary vulnerability. Tools flag the dependencies as having CVEs.

from uap-java.

jmini avatar jmini commented on August 22, 2024

I think it is safe to update SnakeYAML to 2.0.

See release notes: https://bitbucket.org/snakeyaml/snakeyaml/wiki/Changes

PR for this project: #82

from uap-java.

ucjonathan avatar ucjonathan commented on August 22, 2024

Is there an ETA on when the next release will be made that contains 82 and/or 83?

from uap-java.

bpossolo avatar bpossolo commented on August 22, 2024

I don’t have a specific eta but I will do it once I have some time to evaluate all the recent PRs and requests

from uap-java.

ucjonathan avatar ucjonathan commented on August 22, 2024

@bpossolo My suggestion would be to make a release that is only the individual pull request to update the SnakeYAML dependency as it has a security vulnerability.

from uap-java.

bpossolo avatar bpossolo commented on August 22, 2024

from my understanding, the “security vulnerability” is not a real vulnerability as has been pointed out by the maintainers of snakeyml.
It’s only a vulnerability if youre using snakeyml to load untrusted content.

i need to figure out if the best path forward is to use a different lib (doesn’t introduce breaking change) or if it should be done at build time (introduced breaking change)

from uap-java.

wutsi avatar wutsi commented on August 22, 2024

Guys can you please release a new version ...
This is causing issue with project with uap-java and springboot 3.2+

from uap-java.

gupadhyay-accedian avatar gupadhyay-accedian commented on August 22, 2024

Could you please release a version with snake yaml 2.0 ?

from uap-java.

wutsi avatar wutsi commented on August 22, 2024

please.. this is really urgent! Can we release version with snake yaml 2.x?

from uap-java.

bpossolo avatar bpossolo commented on August 22, 2024

I'm pleased to announce version 1.6.1 has been released to Maven Central and the security vulnerability has been addressed.

see here for what's changed
https://github.com/ua-parser/uap-java/releases/tag/v1.6.1

from uap-java.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.