You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I found that in the turbot/steampipe project this is happening because of the ghodss/yaml import. Looking through their issues, its seems they haven't responded to upgrading yet. In ghodss/yaml#81, a user of this library that ran into the same issue created a fork with a fix: https://github.com/invopop/yaml
Can turbot/steampipe either switch to https://github.com/invopop/yaml or avoid using ghodss/yaml to resolve this security vulnerabilty?
The text was updated successfully, but these errors were encountered:
There is a security vulnerability in gopkg.in/yaml.v2: https://security.snyk.io/vuln/SNYK-GOLANG-GOPKGINYAMLV3-2841557
I found that in the turbot/steampipe project this is happening because of the ghodss/yaml import. Looking through their issues, its seems they haven't responded to upgrading yet. In ghodss/yaml#81, a user of this library that ran into the same issue created a fork with a fix: https://github.com/invopop/yaml
Can turbot/steampipe either switch to https://github.com/invopop/yaml or avoid using ghodss/yaml to resolve this security vulnerabilty?
The text was updated successfully, but these errors were encountered: