Skip to content

Conversation

@evansims
Copy link

Changes

This PR bumps the jackson-databind dependency to 2.13.2. This addresses CVE-2020-36518 for that dependency.

References

Testing

Please describe how this can be tested by reviewers. Be specific about anything not tested and reasons why. If this library has unit and/or integration testing, tests should be added for new functionality and existing tests should complete without errors.

  • This change adds test coverage
  • This change has been tested on the latest version of Java or why not

Checklist

@evansims evansims added CH: Security dependencies One or more dependencies are being bumped review:tiny Tiny review labels Mar 13, 2022
@evansims evansims marked this pull request as ready for review March 13, 2022 01:08
@evansims evansims requested a review from a team as a code owner March 13, 2022 01:08
Copy link
Contributor

@poovamraj poovamraj left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@poovamraj poovamraj merged commit 537c19b into master Mar 13, 2022
@jimmyjames jimmyjames modified the milestones: v0-Next, 0.21.0 Mar 14, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CH: Security dependencies One or more dependencies are being bumped review:tiny Tiny review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants