Fork me on GitHub
#clj-yaml
<
2023-02-26
>
lread14:02:24

Looks SnakeYAML 2.0 might be in process of being released https://bitbucket.org/snakeyaml/snakeyaml/wiki/Changes

borkdude14:02:07

Looks like bb users aren’t going to suffer greatly

lread14:02:05

If a CVE gets raised against this new version, I think Andrey might implode

borkdude15:02:19

maybe a PR with an update could help detect if there's any breakages in the defaults

lread15:02:59

If nobody else is interested I can take a peek at upgrading clj-yaml sometime soon. Perceived advantages to upgrade: 1. users would not get current CVE warning for snakeyaml 1.33 2. there might be some security fixes we did not entirely grok