Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade SnakeYAML / Remove SnakeYAML #3145

Closed
iBotPeaches opened this issue Jul 16, 2023 · 2 comments
Closed

Upgrade SnakeYAML / Remove SnakeYAML #3145

iBotPeaches opened this issue Jul 16, 2023 · 2 comments

Comments

@iBotPeaches
Copy link
Owner

iBotPeaches commented Jul 16, 2023

Despite having a secure implementation that doesn't unserialize untrusted user input - we still get flagged on Nexus on every release and get an "urgent" email every month.

It isn't worth explaining anymore. Lets upgrade to v2 SnakeYAML


Alternatively since the YAML spec is quite small - maybe we make our own parser.

@iBotPeaches
Copy link
Owner Author

Looks like no android flavor anymore. Saw an issue issue - https://bitbucket.org/snakeyaml/snakeyaml/issues/1073/missing-artifact-with-classifier-android

Will watch that for a bit. In no hurry since the patched implementation we have of SnakeYAML 1.3.2 isn't vulnerable.

@iBotPeaches iBotPeaches changed the title Upgrade SnakeYAML Upgrade SnakeYAML / Remove SnakeYAML Jul 24, 2023
@iBotPeaches
Copy link
Owner Author

fixed in: #3191

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant