Skip to content

Fixed dependabot alert 5#269

Merged
Xemdo merged 1 commit intomainfrom
fix-cve-2022-28948
Aug 31, 2023
Merged

Fixed dependabot alert 5#269
Xemdo merged 1 commit intomainfrom
fix-cve-2022-28948

Conversation

@Xemdo
Copy link
Copy Markdown
Contributor

@Xemdo Xemdo commented Aug 31, 2023

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

Problem/Feature

https://nvd.nist.gov/vuln/detail/CVE-2022-28948
This CVE affected gopkg.in/yaml.v3 at the previous version of v3.0.0-20210107192922-496545a6307b

While there's no yaml read by the Twitch CLI, thus making it not really affected by this, it's still worth updating since the updated version causes no issues.

Description of Changes:

  • Updated gopkg.in/yaml.v3 to v3.0.0-20220521103104-8f96da9f5d5e

Checklist

  • My code follows the Contribution Guide
  • I have self-reviewed the changes being requested
  • I have made comments on pieces of code that may be difficult to understand for other editors
  • I have updated the documentation (if applicable)

@Xemdo Xemdo merged commit 50f5244 into main Aug 31, 2023
@Xemdo Xemdo deleted the fix-cve-2022-28948 branch August 31, 2023 04:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant