opensearch-project / opensearch-project/common-utils
Re-enable detekt when snakeyaml vulnerability is fixed
Open
Nobody has claimed this yet.
enhancement
infrastructure
- Dominant language
- Kotlin
- Stars
- 30
- Forks
- 117
- Avg merge
- 16h 37m
- Merged PRs (30d)
- 16
Description
Is your feature request related to a problem?
snakeyaml 1.31 is vulnerable. detekt depends on snakeyaml.
So, detekt is disabled for now until snakeyaml vulnerability is fixed. #237
this issue is created to track the progress of re-enabling detekt when snakeyaml vulnerability is fixed.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Review issue #237 and the repository's detekt configuration to confirm that the SnakeYAML vulnerability is fixed. Restore detekt and run the project's checks; done means detekt is enabled without reintroducing the vulnerable dependency.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- kotlin
- Domain
- security, tooling
- Issue type
- Feature
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100