Skip to content

CVE: update testify/yaml dependencies #48

@cboitel

Description

@cboitel

gommon v0.3.0 uses github.com/stretchr/[email protected] which in turns uses gopkg.in/[email protected] which suffers a severe CVE long fixed since there is at least a v2.2.8 and even v2.4.0.

By simply, upgrading the yaml dependency, this would avoid having the CVE reported by security scanning tools (lke sonatype).

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions