From 4c8abad36229ef51eee08bb78e46f8b06ce9034c Mon Sep 17 00:00:00 2001 From: Thomas Crowley Date: Fri, 2 Sep 2022 16:58:17 +1000 Subject: [PATCH] Bump snakeyaml to 1.31. Fixes CVE-2022-25857 (#33) --- project.clj | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/project.clj b/project.clj index 5fca8f6..bd97a6c 100644 --- a/project.clj +++ b/project.clj @@ -16,6 +16,6 @@ :java-source-paths ["src/java"] :javac-options ["-target" "1.7" "-source" "1.7" "-Xlint:-options"] :dependencies - [[org.yaml/snakeyaml "1.26"] + [[org.yaml/snakeyaml "1.31"] [org.flatland/ordered "1.5.9"]] :profiles {:provided {:dependencies [[org.clojure/clojure "1.10.1"]]}})