Safe YAML v1.33.0
This contains a fork of SnakeYAML from when version v1.33 was first published. This includes all the recommended changes to make it safe.
This is a stable release,…
Read MorePublished 02/21/2023
Snake YAML Default Constructor Fix
Drop in replacement for Snake YAML 1.33, this is a fork of the latest changes. The default constructors have been changed to no longer allow remote execution during deserialization.
For more information read - https://bitbucket.org/snakeyaml/snakeyaml/issues/561/cve-2022-1471-vulnerability-in
You probably don’t need this dependency if you’re not familiar with the issue, feel free to just ignore it.
This library is unlikely to get updated beyond importing changes from upstream, so if you have an idea (not security related) please just forward it upstream.
Recommended - If you’re using SnakeYAML as a transitive dependency this is the one you want
Add the following to your pom.xml as a maven dependency, or just download the latest release and import it with your IDE.
<dependency>
<groupId>com.konloch</groupId>
<artifactId>safeyaml</artifactId>
<version>1.33.0</version>
</dependency>
Not Recommended - I recommend using 1.33.0 as this version drops compatability for older features and may cause API breaks if used as a transitive dependency.
Add the following to your pom.xml as a maven dependency, or just download the latest release and import it with your IDE.
<dependency>
<groupId>com.konloch</groupId>
<artifactId>safeyaml</artifactId>
<version>1.34.0</version>
</dependency>
org.yaml.snakeyaml has been maintained along with all of the existing names, none of the API has been changed to maintain 1:1 compatability between libraries.1.34.0 and upstream uses 1.34This contains a fork of SnakeYAML from when version v1.33 was first published. This includes all the recommended changes to make it safe.
This is a stable release,…
Read MoreThis contains a current (02/21/2023) fork of SnakeYAML with the recommended changes to make it safe.
This is more of an experimental release, the default constructor has been…
Read More