From aae665afcadee167f193dd6b89cba338c6d668b1 Mon Sep 17 00:00:00 2001 From: Jeromy Streets Date: Sat, 9 Jul 2022 18:32:56 -0700 Subject: [PATCH] gopkg.in/yaml.v2 has a vunerability #70 - Updated to gopkg.in/yaml.v3. - Verified vunerability resolved with grype. --- config/config.go | 2 +- config/config_test.go | 2 +- go.mod | 8 +++----- go.sum | 12 +++--------- 4 files changed, 8 insertions(+), 16 deletions(-) diff --git a/config/config.go b/config/config.go index 1a01790..535a1dd 100644 --- a/config/config.go +++ b/config/config.go @@ -10,7 +10,7 @@ import ( "strconv" "strings" - yaml "gopkg.in/yaml.v2" + yaml "gopkg.in/yaml.v3" ) var ( diff --git a/config/config_test.go b/config/config_test.go index 4420411..05958f5 100644 --- a/config/config_test.go +++ b/config/config_test.go @@ -8,7 +8,7 @@ import ( "strconv" "testing" - yaml "gopkg.in/yaml.v2" + yaml "gopkg.in/yaml.v3" ) func TestLoad(t *testing.T) { diff --git a/go.mod b/go.mod index 3c30ef3..0225e99 100644 --- a/go.mod +++ b/go.mod @@ -1,7 +1,5 @@ module github.com/halverneus/static-file-server -require ( - github.com/kr/pretty v0.1.0 // indirect - gopkg.in/check.v1 v1.0.0-20180628173108-788fd7840127 // indirect - gopkg.in/yaml.v2 v2.2.2 -) +go 1.18 + +require gopkg.in/yaml.v3 v3.0.1 diff --git a/go.sum b/go.sum index ad03c0f..a62c313 100644 --- a/go.sum +++ b/go.sum @@ -1,10 +1,4 @@ -github.com/kr/pretty v0.1.0 h1:L/CwN0zerZDmRFUapSPitk6f+Q3+0za1rQkzVuMiMFI= -github.com/kr/pretty v0.1.0/go.mod h1:dAy3ld7l9f0ibDNOQOHHMYYIIbhfbHSm3C4ZsoJORNo= -github.com/kr/pty v1.1.1/go.mod h1:pFQYn66WHrOpPYNljwOMqo10TkYh1fy3cYio2l3bCsQ= -github.com/kr/text v0.1.0 h1:45sCR5RtlFHMR4UwH9sdQ5TC8v0qDQCHnXt+kaKSTVE= -github.com/kr/text v0.1.0/go.mod h1:4Jbv+DJW3UT/LiOwJeYQe1efqtUx/iVham/4vfdArNI= +gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405 h1:yhCVgyC4o1eVCa2tZl7eS0r+SDo693bJlVdllGtEeKM= gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= -gopkg.in/check.v1 v1.0.0-20180628173108-788fd7840127 h1:qIbj1fsPNlZgppZ+VLlY7N33q108Sa+fhmuc+sWQYwY= -gopkg.in/check.v1 v1.0.0-20180628173108-788fd7840127/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= -gopkg.in/yaml.v2 v2.2.2 h1:ZCJp+EgiOT7lHqUV2J862kp8Qj64Jo6az82+3Td9dZw= -gopkg.in/yaml.v2 v2.2.2/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI= +gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA= +gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=