Skip to content
This repository has been archived by the owner on Feb 8, 2024. It is now read-only.

Update dependency PyYAML to v5.4 (main) - autoclosed #505

Closed

Conversation

mend-for-github-com[bot]
Copy link
Contributor

@mend-for-github-com mend-for-github-com bot commented Jul 15, 2021

This PR contains the following updates:

Package Update Change
PyYAML (source) minor ==5.1.2 -> ==5.4

By merging this PR, the below issues will be automatically resolved and closed:

Severity CVSS Score CVE GitHub Issue
High 9.8 CVE-2020-1747 #269
High 9.8 CVE-2019-20477 #270
High 9.8 CVE-2020-14343 #271

Release Notes

yaml/pyyaml

v5.4

Compare Source

v5.3.1

Compare Source

v5.3

Compare Source

v5.2

Compare Source


  • If you want to rebase/retry this PR, check this box.

@cortx-admin
Copy link

Can one of the admins verify this patch?

@ajaysrivas
Copy link
Contributor

@indrajitzagade This needs to be discussed in integration meeting, impacts packaging of 3rd party modules and will require RE team's help.

@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/main-pyyaml-5.x branch from 8fe27f6 to 928b753 Compare July 19, 2021 08:19
@indrajitzagade
Copy link
Contributor

@indrajitzagade This needs to be discussed in integration meeting, impacts packaging of 3rd party modules and will require RE team's help.

Sure @ajaysrivas

@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/main-pyyaml-5.x branch 4 times, most recently from 0182bc1 to 96942a6 Compare July 27, 2021 14:13
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/main-pyyaml-5.x branch from 96942a6 to f8f96b5 Compare July 28, 2021 07:54
@stale
Copy link

stale bot commented Aug 1, 2021

This issue/pull request has been marked as needs attention as it has been left pending without new activity for 4 days. Tagging @indrajitzagade @ajaysrivas for appropriate assignment. Sorry for the delay & Thank you for contributing to CORTX. We will get back to you as soon as possible.

@stale stale bot added the needs-attention label Aug 1, 2021
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/main-pyyaml-5.x branch 3 times, most recently from 3084c06 to 4e45908 Compare August 11, 2021 06:36
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/main-pyyaml-5.x branch 2 times, most recently from ff5e238 to 0fa969a Compare August 20, 2021 06:38
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/main-pyyaml-5.x branch 3 times, most recently from 895e0bc to 70737b9 Compare September 1, 2021 08:25
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/main-pyyaml-5.x branch from 70737b9 to 44d494f Compare September 1, 2021 13:44
@mend-for-github-com
Copy link
Contributor Author

Autoclosing Skipped

This PR has been flagged for autoclosing, however it is being skipped due to the branch being already modified. Please close/delete it manually or report a bug if you think this is in error.

@mend-for-github-com mend-for-github-com bot changed the title Update dependency PyYAML to v5.4 (main) Update dependency PyYAML to v5.4 (main) - autoclosed Oct 31, 2021
@mend-for-github-com mend-for-github-com bot deleted the whitesource-remediate/main-pyyaml-5.x branch October 31, 2021 12:34
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
needs-attention security fix Security fix generated by WhiteSource
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants