Given https://github.com/go-yaml/yaml/blob/v3/README.md
We need to migrate to a supported library, policy suggests we treat this as a high severity vulnerability.
YMMV but https://github.com/kubernetes-sigs/yaml may be the best bet (its not a wrapper round go-yaml now).