jmespath / jmespath/go-jmespath
Fix SNYK-GOLANG-GOPKGINYAMLV3-2841557
Open
- Dominant language
- Go
- Stars
- 621
- Forks
- 101
- PR merge metrics
- No merged PRs in 30d
Description
Hey all - I'm trying to solve https://security.snyk.io/vuln/SNYK-GOLANG-GOPKGINYAMLV3-2841557 which I'm getting via https://github.com/aws/aws-sdk-go. Usually, I'd put a PR in to bump the dependency in the tree but as it seems the link is testify which has been submodule here due to lock testify at `1.5.1` maintaining compatibility with Go <1.12 I'm not 100% on the next steps.
Does anyone with a better understanding of this package have any pointers on how to mitigate this vulnerability?
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.