Skip to content

[1.10.x] Bump jackson from 2.19.2 to 2.21.2 to fix GHSA-72hv-8253-57qq#15847

Merged
amogh-jahagirdar merged 2 commits intoapache:1.10.xfrom
manuzhang:upgrade-jackson-1.10.x
Apr 2, 2026
Merged

[1.10.x] Bump jackson from 2.19.2 to 2.21.2 to fix GHSA-72hv-8253-57qq#15847
amogh-jahagirdar merged 2 commits intoapache:1.10.xfrom
manuzhang:upgrade-jackson-1.10.x

Conversation

@manuzhang
Copy link
Copy Markdown
Member

No description provided.

@manuzhang manuzhang added this to the Iceberg 1.10.2 milestone Apr 1, 2026
@amogh-jahagirdar
Copy link
Copy Markdown
Contributor

Thanks @manuzhang can we update the kafka-connect hive/runtime license and notices?

@manuzhang
Copy link
Copy Markdown
Member Author

@amogh-jahagirdar where do we need to update?

Copy link
Copy Markdown
Contributor

@amogh-jahagirdar amogh-jahagirdar left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you @manuzhang I just had a comment on what I think is an unnecessary change and the exact minor version in the license/notice, once that's addressed I'll go ahead and merge

Project URL: https://github.com/google/flatbuffers
License (from POM): The Apache License, Version 2.0 - http://www.apache.org/licenses/LICENSE-2.0.txt

-------------------------------------------------------------------------------- No newline at end of file
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why did this change?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No new line at the end of the file.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd prefer to try to avoid these kinds of changes when they're not needed but It's fine.


Group: com.fasterxml.jackson.core Name: jackson-annotations Version: 2.19.2
Group: com.fasterxml.jackson.core Name: jackson-databind Version: 2.19.2
Group: com.fasterxml.jackson.core Name: jackson-annotations Version: 2.21
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Isn't this also 2.21.2?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nope, jackson-annotations got its own version since 2.20.
https://mvnrepository.com/artifact/com.fasterxml.jackson.core/jackson-annotations

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the pointer!

@amogh-jahagirdar
Copy link
Copy Markdown
Contributor

Thanks @manuzhang

@amogh-jahagirdar amogh-jahagirdar merged commit 1f76a49 into apache:1.10.x Apr 2, 2026
42 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants