Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[fix][sec] Bump snakeyaml to 1.32 for CVE-2022-38752 #17779

Merged
merged 3 commits into from
Sep 24, 2022

Conversation

tisonkun
Copy link
Member

See CVE-2022-38752.

Documentation

  • doc-required
    (Your PR needs to update docs and you will update later)

  • doc-not-needed
    (Please explain why)

  • doc
    (Your PR contains doc changes)

  • doc-complete
    (Docs have been already added)

Matching PR in forked repository

PR in forked repository: trivial to not have one.

@tisonkun
Copy link
Member Author

cc @nicoloboschi @lhotari

@github-actions github-actions bot added the doc-not-needed Your PR changes do not impact docs label Sep 21, 2022
@Jason918 Jason918 changed the title fix(sec): bump snakeyaml to 1.32 for CVE-2022-38752 [fix][sec] Bump snakeyaml to 1.32 for CVE-2022-38752 Sep 22, 2022
Copy link
Contributor

@Jason918 Jason918 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@tisonkun
Copy link
Member Author

/pulsarbot run-failure-checks

@Jason918
Copy link
Contributor

@tisonkun we need to update the "LICENSE.bin.txt" files? like #17466

@tisonkun
Copy link
Member Author

@Jason918 you're right. Let me check and update them.

@tisonkun
Copy link
Member Author

Updated.

@tisonkun
Copy link
Member Author

/pulsarbot run-failure-checks

@Jason918 Jason918 merged commit ec8b586 into apache:master Sep 24, 2022
@tisonkun tisonkun deleted the fix-CVE-2022-38752 branch September 24, 2022 04:45
Jason918 pushed a commit that referenced this pull request Sep 24, 2022
nicoloboschi pushed a commit to datastax/pulsar that referenced this pull request Sep 26, 2022
@congbobo184
Copy link
Contributor

could you please cherry-pick this PR to branch-2.9? thanks.

@tisonkun
Copy link
Member Author

@congbobo184 created at #18467.

@congbobo184 congbobo184 added the cherry-picked/branch-2.9 Archived: 2.9 is end of life label Nov 15, 2022
lhotari pushed a commit that referenced this pull request Jan 3, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants