Skip to content

Bump jackson-databind dependency#887

Merged
Avery-Dunn merged 1 commit intodevfrom
avdunn/dependency-update
Dec 17, 2024
Merged

Bump jackson-databind dependency#887
Avery-Dunn merged 1 commit intodevfrom
avdunn/dependency-update

Conversation

@Avery-Dunn
Copy link
Copy Markdown
Contributor

Resolves #882: there is a CVE in jackson-databind that they dispute, but regardless it is causing our library to be flagged in compliance tools and it's easier for us to just update.

@Avery-Dunn Avery-Dunn merged commit ff22fd2 into dev Dec 17, 2024
@Avery-Dunn Avery-Dunn deleted the avdunn/dependency-update branch January 21, 2025 21:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feature Request] Bump jackson dependency due to possible CVE

3 participants