yogthos / markdown-clj

Markdown parser in Clojure
Eclipse Public License 1.0
540 stars 120 forks source link

Bump `clj-yaml` to Patch Vulnerable Dependency #187

Closed dbrrr closed 2 years ago

dbrrr commented 2 years ago

Issue: clj-yaml was bumped today to fix a vulnerability in snakeyaml -- our scanner is now picking up markdown-clj as including the vulnerable dep :)

Fix: Bump version of clj-yaml

yogthos commented 2 years ago

thanks!