hortonworks/registry

Upgrade Dropwizard to v2.1.2

gcsaba2 opened this issue · 0 comments

Also remove direct snakeyaml dependency and let it arrive from Dropwizard

Our end goal is to have snakeyaml on version 1.32+ due to CVEs. The current version of Dropwizard imports 1.31 which resolves some of the CVEs but not all of them. We will need to wait for the next release of Dropwizard (hopefully within a month) which should upgrade snakeyaml to 1.33