Skip to content

Upgrading SnakeYAML to 2.0 to address CVE-2022-1471

David Diederich requested to merge upgrade-snakeyaml-directly into master

This upgrades the SnakeYAML dependency to be version 2.0, addressing a critical security vulnerability (CVE-2022-1471).

Closes #6

This is One of Two Options

I have two different approaches to getting this library to link to SnakeYAML 2.0. The other is !79 (closed).

At most one of these should be merged. The other should be closed.

Merge request reports