Skip to content

Bump go-yaml version to cover fixed ddos heuristic#1751

Merged
jtopjian merged 1 commit intogophercloud:masterfrom
petrkotas:go-yaml-fix
Oct 17, 2019
Merged

Bump go-yaml version to cover fixed ddos heuristic#1751
jtopjian merged 1 commit intogophercloud:masterfrom
petrkotas:go-yaml-fix

Conversation

@petrkotas
Copy link
Copy Markdown
Contributor

go-yaml preceding 2.2.4 had vulnerability to ddos attack via billion laughs bomb.
Such attack lead to program to be unresponsive.

Provided fix by upgrading the module dependencies.

For #1750

Signed-off-by: Petr Kotas petr.kotas@gmail.com

@coveralls
Copy link
Copy Markdown

coveralls commented Oct 17, 2019

Coverage Status

Coverage remained the same at 76.995% when pulling 39612bb on petrkotas:go-yaml-fix into f2af868 on gophercloud:master.

@theopenlab-ci
Copy link
Copy Markdown

theopenlab-ci bot commented Oct 17, 2019

Build failed.

go-yaml preceding 2.2.4 had vulnerability to ddos attack via billion
laughs bomb.
Such attack lead to program to be unresponsive.

Signed-off-by: Petr Kotas <petr.kotas@gmail.com>
@theopenlab-ci
Copy link
Copy Markdown

theopenlab-ci bot commented Oct 17, 2019

Build failed.

@jtopjian
Copy link
Copy Markdown
Contributor

The job failure looks to be separate from this PR.

Copy link
Copy Markdown
Contributor

@jtopjian jtopjian left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM - thank you!

@jtopjian jtopjian merged commit 47e5c17 into gophercloud:master Oct 17, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants