Fix CVE-2022-28948 - Remove gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c
#146
Milestone
gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c
#146
Github Advisor reported a vulnerable package:
gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c
Here is the CVE report.
One of my application uses
testify
package as dependency, in the current setup my application is vulnerable, this is why I am asking from you to correct this vulnerability.I checked the dependency usage in the following way:
From the above dependency tree can be seen that the vulnerable package is pulled in through
github.com/stretchr/[email protected]
.I would like to ask from you to correct this package vulnerability.
The text was updated successfully, but these errors were encountered: