diff --git a/DEPENDENCIES b/DEPENDENCIES index f334c5f95..87e289d24 100644 --- a/DEPENDENCIES +++ b/DEPENDENCIES @@ -655,6 +655,7 @@ maven/mavencentral/org.xmlunit/xmlunit-core/2.9.1, Apache-2.0, approved, #6272 maven/mavencentral/org.xmlunit/xmlunit-placeholders/2.9.1, Apache-2.0, approved, clearlydefined maven/mavencentral/org.yaml/snakeyaml/1.33, Apache-2.0, approved, clearlydefined maven/mavencentral/org.yaml/snakeyaml/2.2, Apache-2.0 AND (Apache-2.0 OR BSD-3-Clause OR EPL-1.0 OR GPL-2.0-or-later OR LGPL-2.1-or-later), approved, #10232 +maven/mavencentral/org.yaml/snakeyaml/2.3, Apache-2.0 AND (Apache-2.0 AND BSD-3-Clause AND EPL-1.0 AND GPL-2.0-or-later AND LGPL-2.1-or-later), restricted, #16046 maven/mavencentral/software.amazon.awssdk/annotations/2.26.27, Apache-2.0, approved, clearlydefined maven/mavencentral/software.amazon.awssdk/annotations/2.27.12, Apache-2.0, approved, clearlydefined maven/mavencentral/software.amazon.awssdk/apache-client/2.26.27, Apache-2.0, approved, clearlydefined diff --git a/build.gradle.kts b/build.gradle.kts index e8c261e19..b22e7e065 100644 --- a/build.gradle.kts +++ b/build.gradle.kts @@ -66,7 +66,7 @@ allprojects { testImplementation(platform("org.junit:junit-bom:5.11.0")) constraints { - implementation("org.yaml:snakeyaml:2.2") { + implementation("org.yaml:snakeyaml:2.3") { because("version 1.33 has vulnerabilities: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1471.") } implementation("net.minidev:json-smart:2.5.1") {