-
Notifications
You must be signed in to change notification settings - Fork 3.3k
Update pyyaml from 3.1.2 to 5.4.1 #1306
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update pyyaml from 3.1.2 to 5.4.1 #1306
Conversation
/lgtm |
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: palnabarun, yliaog The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Issues go stale after 90d of inactivity. If this issue is safe to close now please do so with Send feedback to sig-testing, kubernetes/test-infra and/or fejta. |
Stale issues rot after 30d of inactivity. If this issue is safe to close now please do so with Send feedback to sig-contributor-experience at kubernetes/community. |
/remove-lifecycle rotten |
/retitle Update pyyaml from 3.1.2 to 5.4.1 |
/lgtm |
Rebasing this on top of changes in #1480 to verify if just dropping Python 3.5 resolves issues with resolving dependencies. |
/lgtm |
5.3.1 fixed partially vulnerabilities disclosed in CVE-2020-1747. A complete fix was debated at yaml/pyyaml#420 and eventually got patched in 5.4.1 Changeset: yaml/pyyaml@3.12...5.4.1 Signed-off-by: Nabarun Pal <[email protected]>
@yliaog -- needs another LGTM. :) |
/lgtm |
/hold cancel |
5.3.1 fixed partially vulnerabilities disclosed in CVE-2020-1747.
A complete fix was debated at yaml/pyyaml#420 and eventually got patched in 5.4.1
Changeset: yaml/pyyaml@3.12...5.4.1
I skimmed through the changeset and didn't see any apparent breaking changes.
But I will go through that in more detail. Putting a hold due to the same.
/hold