Skip to content

Conversation

@Xemdo
Copy link
Contributor

@Xemdo Xemdo commented Aug 31, 2023

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

Problem/Feature

https://nvd.nist.gov/vuln/detail/CVE-2022-28948
This CVE affected gopkg.in/yaml.v3 at the previous version of v3.0.0-20210107192922-496545a6307b

While there's no yaml read by the Twitch CLI, thus making it not really affected by this, it's still worth updating since the updated version causes no issues.

Description of Changes:

  • Updated gopkg.in/yaml.v3 to v3.0.0-20220521103104-8f96da9f5d5e

Checklist

  • My code follows the Contribution Guide
  • I have self-reviewed the changes being requested
  • I have made comments on pieces of code that may be difficult to understand for other editors
  • I have updated the documentation (if applicable)

@Xemdo Xemdo merged commit 50f5244 into main Aug 31, 2023
@Xemdo Xemdo deleted the fix-cve-2022-28948 branch August 31, 2023 04:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants