Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(sec): upgrade gopkg.in/yaml.v3 to 3.0.0 #2112

Merged
merged 1 commit into from
Nov 11, 2022

Conversation

chncaption
Copy link
Contributor

What happened?

There are 1 security vulnerabilities found in gopkg.in/yaml.v3 v3.0.0-20210107192922-496545a6307b

What did I do?

Upgrade gopkg.in/yaml.v3 from v3.0.0-20210107192922-496545a6307b to 3.0.0 for vulnerability fix

What did you expect to happen?

Ideally, no insecure libs should be used.

The specification of the pull request

PR Specification from OSCS

@AlexStocks AlexStocks changed the base branch from master to 3.0 November 8, 2022 05:07
@AlexStocks
Copy link
Contributor

thanks for your pr. dubbogo main branch is 3.0. I have changed your pr's target branch.

@codecov-commenter
Copy link

Codecov Report

Merging #2112 (b452086) into 3.0 (5903520) will decrease coverage by 0.05%.
The diff coverage is n/a.

@@            Coverage Diff             @@
##              3.0    #2112      +/-   ##
==========================================
- Coverage   44.74%   44.68%   -0.06%     
==========================================
  Files         281      281              
  Lines       16864    16864              
==========================================
- Hits         7546     7536      -10     
- Misses       8527     8540      +13     
+ Partials      791      788       -3     
Impacted Files Coverage Δ
cluster/cluster/base/cluster_invoker.go 24.44% <0.00%> (-13.34%) ⬇️
cluster/loadbalance/ringhash/ring.go 87.32% <0.00%> (+2.81%) ⬆️

📣 We’re building smart automated test selection to slash your CI/CD build times. Learn more

@zhaoyunxing92 zhaoyunxing92 merged commit c9920e8 into apache:3.0 Nov 11, 2022
@justxuewei justxuewei added this to the v3.0.4 milestone Dec 4, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants