You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@atlas.apache.org by GitBox <gi...@apache.org> on 2020/09/07 10:11:44 UTC

[GitHub] [atlas] crazylab opened a new pull request #109: Upgrade snakeyaml to a version without CVE-2017-18640

crazylab opened a new pull request #109:
URL: https://github.com/apache/atlas/pull/109


   - Maven package cassandra-all has transitive dependency on org.yaml:snakeyaml:1.11 which has CVE-2017-18640:https://nvd.nist.gov/vuln/detail/CVE-2017-18640
   - Raised a PR to Cassandra to upgrade the version of snakeyaml to 1.26 where the CVE got fixed : https://github.com/apache/cassandra/pull/736
   - Upgrade to the latest version of cassandra-all once new releases become available


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [atlas] crazylab closed pull request #109: Upgrade snakeyaml to a version without CVE-2017-18640

Posted by GitBox <gi...@apache.org>.
crazylab closed pull request #109:
URL: https://github.com/apache/atlas/pull/109


   


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org