summaryrefslogtreecommitdiff
path: root/go.mod
diff options
context:
space:
mode:
authorLokesh Mandvekar <lsm5@fedoraproject.org>2022-05-31 13:01:50 -0400
committerLokesh Mandvekar <lsm5@fedoraproject.org>2022-05-31 13:01:50 -0400
commitcef044d859edf255d146ce1a07b7bc735b045a1f (patch)
tree7c3aa1c42f16e961cd57d664648e66e0ba9be683 /go.mod
parentdc67e6a182a09c8b65ef139fb9f15ddfdecae70f (diff)
downloadpodman-cef044d859edf255d146ce1a07b7bc735b045a1f.tar.gz
podman-cef044d859edf255d146ce1a07b7bc735b045a1f.tar.bz2
podman-cef044d859edf255d146ce1a07b7bc735b045a1f.zip
Bump gopkg.in/yaml.v3 to v3.0.1
v3.0.1 resolves GHSA-hp87-p4gw-j4gq - CVE-2022-28948. While podman doesn't appear to be vulnerable to the CVE as the concerned code isn't being called, this update should silence a dependabot alert. Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
Diffstat (limited to 'go.mod')
-rw-r--r--go.mod1
1 files changed, 1 insertions, 0 deletions
diff --git a/go.mod b/go.mod
index 1880134e9..14aea5f3d 100644
--- a/go.mod
+++ b/go.mod
@@ -72,4 +72,5 @@ require (
google.golang.org/protobuf v1.28.0
gopkg.in/inf.v0 v0.9.1
gopkg.in/yaml.v2 v2.4.0
+ gopkg.in/yaml.v3 v3.0.1 // indirect
)