From 607dcfa5ff9f4cca0887023027433a68e1182528 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 17 Sep 2025 01:18:35 +0000 Subject: [PATCH] build(deps): bump org.yaml:snakeyaml from 1.33 to 2.5 Bumps [org.yaml:snakeyaml](https://bitbucket.org/snakeyaml/snakeyaml) from 1.33 to 2.5. - [Commits](https://bitbucket.org/snakeyaml/snakeyaml/branches/compare/snakeyaml-2.5..snakeyaml-1.33) --- updated-dependencies: - dependency-name: org.yaml:snakeyaml dependency-version: '2.5' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- gradle/libs.versions.toml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/gradle/libs.versions.toml b/gradle/libs.versions.toml index e8245d9..58a26d7 100644 --- a/gradle/libs.versions.toml +++ b/gradle/libs.versions.toml @@ -26,7 +26,7 @@ openapi-generator-plugin-compat = "7.10.0" # Minimum supported for compileOnly # These versions are specifically chosen to address known CVEs: # - snakeyaml: 2.3 (fixes CVE-2022-1471 - CRITICAL) # - commons-lang3: 3.18.0 (fixes CVE-2025-48924 - MEDIUM) -snakeyaml = "2.3" +snakeyaml = "2.5" commons-lang3 = "3.18.0" # ===============================================================================================