Skip to content

Security: Bump jackson-databind to 2.13.2.2#144

Merged
poovamraj merged 2 commits intomasterfrom
security/bump-jackson-databind
Mar 30, 2022
Merged

Security: Bump jackson-databind to 2.13.2.2#144
poovamraj merged 2 commits intomasterfrom
security/bump-jackson-databind

Conversation

@evansims
Copy link
Copy Markdown

@evansims evansims commented Mar 26, 2022

This PR bumps the jackson-databind dependency to 2.13.2.2 to address CVE-2020-36518 in that library


Re: FasterXML/jackson-databind#3428
Build is currently failing due to an upstream issue; holding until resolved.


A package fix was released as 2.13.2.2. I've updated the PR and marked as ready for review.

@evansims evansims added CH: Security dependencies One or more dependencies are being bumped labels Mar 26, 2022
@evansims evansims changed the title Security: Bump jackson-databind to 2.13.2.1 Security: Bump jackson-databind to 2.13.2.2 Mar 29, 2022
@evansims evansims added the review:tiny Tiny review label Mar 29, 2022
@evansims evansims marked this pull request as ready for review March 29, 2022 18:08
@evansims evansims requested a review from a team as a code owner March 29, 2022 18:08
@poovamraj poovamraj added this to the v0-Next milestone Mar 30, 2022
@poovamraj poovamraj merged commit a74946f into master Mar 30, 2022
@poovamraj poovamraj modified the milestones: v0-Next, 0.21.1 Mar 30, 2022
@poovamraj poovamraj mentioned this pull request Mar 30, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CH: Security dependencies One or more dependencies are being bumped review:tiny Tiny review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants