Skip to content

Bump transitive jackson dependencies in auth0 libraries#68

Merged
poovamraj merged 1 commit intomasterfrom
bump-jackson-transitive-dependency
Mar 30, 2022
Merged

Bump transitive jackson dependencies in auth0 libraries#68
poovamraj merged 1 commit intomasterfrom
bump-jackson-transitive-dependency

Conversation

@poovamraj
Copy link
Copy Markdown
Contributor

This PR bumps the auth0 libraries using jackson-databind dependency to 2.13.2.2 to address CVE-2020-36518 in that library

@poovamraj poovamraj requested a review from a team as a code owner March 30, 2022 09:46
@poovamraj poovamraj added CH: Security dependencies One or more dependencies are being bumped review:tiny Tiny review labels Mar 30, 2022
@poovamraj poovamraj added this to the v1-Next milestone Mar 30, 2022
@poovamraj poovamraj merged commit 0b3aa11 into master Mar 30, 2022
@poovamraj poovamraj modified the milestones: v1-Next, 1.5.1 Mar 30, 2022
@poovamraj poovamraj mentioned this pull request Mar 30, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CH: Security dependencies One or more dependencies are being bumped review:tiny Tiny review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants