sbt-typelevel icon indicating copy to clipboard operation
sbt-typelevel copied to clipboard

snakeyaml-2.0 for 0.5?

Open rossabaker opened this issue 2 years ago • 5 comments

Would it be possible to upgrade to snakeyaml-2.0 for the 0.5 release? There's a nuisance CVE on 1.33.

One question would be how much of the rest of the SBT ecosystem might use snakeyaml-1.x dependencies. 2.x drops some deprecated methods and is not binary compatible.

rossabaker avatar May 02 '23 17:05 rossabaker