Comments (3)
Reported the issue to github.com/stretchr/objx
: stretchr/objx#146
from testify.
v1.8.4 does not have this vulnerability:
Line 9 in f97607b
It is not a problem if vulnerable modules appear in your graph. The vulnerable yaml module will not be built into any of your binaries using testify >= 1.8.4.
from testify.
I could not really differentiate what is compiled into the binaries and what is not.
The go.mod
and go.sum
file contains packages that needed for production and test environment.
This way I would like to ask from you to integrate this solution: stretchr/objx#146 (comment) - after it reaches the publish.
from testify.
Related Issues (20)
- Assert: go test output shows subtests that fail as PASS HOT 3
- `YAMLEq` does not validate YAML HOT 1
- Is it possible to assert for multiple allowed values? HOT 2
- Proposal: guard or support comparing with untyped nil HOT 5
- assert/require.Len doesn't print anything if the slice is too long HOT 7
- Allow user to skip (ignore) specific caller frames in assert.CallerInfo() HOT 1
- Unexpected call when interface is parameter HOT 4
- How can I get coverage in the Suite package HOT 6
- assert: Equal does not consider Zone information in time.Time
- Update Github actions workflows from nodejs 16 to nodejs 20 before "Spring 2024" HOT 1
- mock: Call.NotBefore still expects calls removed with Call.Unset HOT 6
- unnecessary/incorrect log call in AssertExpectations HOT 2
- Data race when mock is called with refernce to same object as expectation HOT 1
- assert fails and expects to dereference a reference HOT 1
- Add GoLang 1.22 to CI Testing Matrix for Package Compatibility Verification HOT 2
- error while importing github.com/stretchr/testify/suite: read C:\Program Files\Go\src\math\huge_test.go: unexpected NUL in input HOT 1
- AnythingOfType is marked deprecated on pkgsite HOT 1
- .On().Return() doesn't enforce expectation for the returned value HOT 1
- v1.9.0 breaks float comparisons with EqualValues HOT 6
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from testify.