scopely-devops / skew

Apache License 2.0
242 stars 70 forks source link

Use yaml.safe_load #137

Closed avram closed 5 years ago

avram commented 5 years ago

Addressing https://nvd.nist.gov/vuln/detail/CVE-2017-18342; cannot just update pyyaml because the new version drops certain Python versions