The gopkg.in/yaml.v2 package has a potential crash when parsing malicious input. Although we only use the yaml package to parse trusted configuration, update to v3 anyway. |
||
|---|---|---|
| .. | ||
| alexcesaro/statsd.v2 | ||
| fsnotify.v1 | ||
| square/go-jose.v2 | ||
| tomb.v1 | ||
| yaml.v3 | ||
The gopkg.in/yaml.v2 package has a potential crash when parsing malicious input. Although we only use the yaml package to parse trusted configuration, update to v3 anyway. |
||
|---|---|---|
| .. | ||
| alexcesaro/statsd.v2 | ||
| fsnotify.v1 | ||
| square/go-jose.v2 | ||
| tomb.v1 | ||
| yaml.v3 | ||