You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
GitHub complains that the used version of pyyaml is smaller than 4.2b1 which is affected by CVE-2017-18342
I don't really get why it is considered as high severity since it only affects the non-recommended way of using pyyaml but nevertheless it generates emails on every push to every team member and shows annoying warning signs on almost every page.
Steps to reproduce
Set up a repository with pipenv and install connexion (need to have the affected version of pyyaml in the Pipfile.lock).
The text was updated successfully, but these errors were encountered:
From the folks behind pyyaml yaml/pyyaml#259 (comment)
There's a pyyaml release planned in a few days that will resolve this issue.
After it is released, we can work with our dependencies to bump to that version.
Description
GitHub complains that the used version of pyyaml is smaller than 4.2b1 which is affected by CVE-2017-18342
I don't really get why it is considered as high severity since it only affects the non-recommended way of using pyyaml but nevertheless it generates emails on every push to every team member and shows annoying warning signs on almost every page.
Steps to reproduce
Set up a repository with pipenv and install connexion (need to have the affected version of pyyaml in the Pipfile.lock).
The text was updated successfully, but these errors were encountered: