Bumps gopkg.in/yaml.v2 from 2.2.2 to 2.2.8. This update includes security fixes.
Vulnerabilities fixed
Excessive Platform Resource Consumption within a Loop in Kubernetes
The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML.
YAML Go package vulnerable to denial of service
Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector.
yaml package for Go can consume excessive amounts of CPU or memory
Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory
Dependabot commands
You can trigger Dependabot actions by commenting on this MR
$dependabot rebase will rebase this MR
$dependabot recreate will recreate this MR rewriting all the manual changes and resolving conflicts
Bumps gopkg.in/yaml.v2 from 2.2.2 to 2.2.8. **This update includes security fixes.**
<details>
<summary>Vulnerabilities fixed</summary>
<blockquote>
<p><strong>Excessive Platform Resource Consumption within a Loop in Kubernetes</strong>
The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML.</p>
<p>Patched versions: 2.2.8
Affected versions: < 2.2.8</p>
</blockquote>
<blockquote>
<p><strong>YAML Go package vulnerable to denial of service</strong>
Due to unbounded alias chasing, a maliciously crafted YAML file can cause the system to consume significant system resources. If parsing user input, this may be used as a denial of service vector.</p>
<p>Patched versions: 2.2.3
Affected versions: < 2.2.3</p>
</blockquote>
<blockquote>
<p><strong>yaml package for Go can consume excessive amounts of CPU or memory</strong>
Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory</p>
<p>Patched versions: 2.2.4
Affected versions: < 2.2.4</p>
</blockquote>
</details>
<br />
---
<details>
<summary>Dependabot commands</summary>
<br />
You can trigger Dependabot actions by commenting on this MR
- `$dependabot rebase` will rebase this MR
- `$dependabot recreate` will recreate this MR rewriting all the manual changes and resolving conflicts
</details>
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Bumps gopkg.in/yaml.v2 from 2.2.2 to 2.2.8. This update includes security fixes.
Vulnerabilities fixed
Dependabot commands
You can trigger Dependabot actions by commenting on this MR
$dependabot rebasewill rebase this MR$dependabot recreatewill recreate this MR rewriting all the manual changes and resolving conflictsadded 1 commit
Compare with previous version
added 4 commits
master121276f6- [Security] Bump gopkg.in/yaml.v2 from 2.2.2 to 2.2.8Compare with previous version