Skip to content

Bump jackson-databind dependency to 2.13.2#411

Merged
poovamraj merged 1 commit intomasterfrom
chore/update-jackson-databind
Mar 13, 2022
Merged

Bump jackson-databind dependency to 2.13.2#411
poovamraj merged 1 commit intomasterfrom
chore/update-jackson-databind

Conversation

@evansims
Copy link
Copy Markdown
Contributor

Changes

This PR bumps the jackson-databind dependency to 2.13.2. This addresses CVE-2020-36518 for that dependency.

References

Testing

Please describe how this can be tested by reviewers. Be specific about anything not tested and reasons why. If this library has unit and/or integration testing, tests should be added for new functionality and existing tests should complete without errors.

  • This change adds test coverage
  • This change has been tested on the latest version of Java or why not

Checklist

@evansims evansims added CH: Security dependencies One or more dependencies are being bumped review:tiny Tiny review labels Mar 13, 2022
@evansims evansims marked this pull request as ready for review March 13, 2022 01:07
@evansims evansims requested a review from a team as a code owner March 13, 2022 01:07
@poovamraj poovamraj merged commit 427ebb3 into master Mar 13, 2022
@jimmyjames jimmyjames modified the milestones: v1-Next, 1.40.0 Mar 14, 2022
@evansims evansims deleted the chore/update-jackson-databind branch July 5, 2022 20:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CH: Security dependencies One or more dependencies are being bumped review:tiny Tiny review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants