Skip to content

Revert "Update SnakeYAML-Engine to 3.0.1"#785

Merged
headius merged 1 commit intomasterfrom
revert-781-update_snakeyaml
Mar 23, 2026
Merged

Revert "Update SnakeYAML-Engine to 3.0.1"#785
headius merged 1 commit intomasterfrom
revert-781-update_snakeyaml

Conversation

@headius
Copy link
Contributor

@headius headius commented Mar 23, 2026

Reverts #781

I did not realize that SnakeYAML 3+ has a minimum Java requirement of 11, which would break Psych for JRuby 9.4 users that are still on Java 8.

Rather than try to force that issue, and because this wasn't really a security issue to begin with, I'm reverting the change for now.

We'll look at bumping Psych up at some point in the future after JRuby 9.4 has been EOL for a while.

Just to repeat: there's really no security issue here, as the dependency in question was only used at test time by SnakeYAML 2.x.

@headius headius merged commit 2ac42a0 into master Mar 23, 2026
164 checks passed
@headius headius deleted the revert-781-update_snakeyaml branch March 23, 2026 21:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant