Skip to content
This repository has been archived by the owner on Aug 2, 2022. It is now read-only.

Bumps jackson version #466

Merged
merged 1 commit into from
Jul 19, 2022

Conversation

downsrob
Copy link
Contributor

Signed-off-by: Clay Downs [email protected]

Issue #, if available:

Description of changes:
Bumps jackson dependency from 2.11.4 to 2.13.2.2 to resolve CVE-2020-36518

By making a contribution to this project, I certify that:

(a) The contribution was created in whole or in part by me and I
have the right to submit it under the open source license
indicated in the file; or

(b) The contribution is based upon previous work that, to the best
of my knowledge, is covered under an appropriate open source
license and I have the right under that license to submit that
work with modifications, whether created in whole or in part
by me, under the same open source license (unless I am
permitted to submit under a different license), as indicated
in the file; or

(c) The contribution was provided directly to me by some other
person who certified (a), (b) or (c) and I have not modified
it.

(d) I understand and agree that this project and the contribution
are public and that a record of the contribution (including all
personal information I submit with it, including my sign-off) is
maintained indefinitely and may be redistributed consistent with
this project or the open source license(s) involved.

Signed-off-by: Clay Downs <[email protected]>
@codecov
Copy link

codecov bot commented Jul 19, 2022

Codecov Report

Merging #466 (37b8491) into main (a53b049) will decrease coverage by 0.43%.
The diff coverage is n/a.

@@             Coverage Diff              @@
##               main     #466      +/-   ##
============================================
- Coverage     77.39%   76.96%   -0.44%     
+ Complexity     1588     1585       -3     
============================================
  Files           199      199              
  Lines          8579     8579              
  Branches       1370     1370              
============================================
- Hits           6640     6603      -37     
- Misses         1187     1229      +42     
+ Partials        752      747       -5     
Impacted Files Coverage Δ
...statemanagement/model/destination/CustomWebhook.kt 65.21% <0.00%> (-28.99%) ⬇️
...nt/indexstatemanagement/ManagedIndexCoordinator.kt 65.61% <0.00%> (-9.10%) ⬇️
...ent/indexstatemanagement/util/ManagedIndexUtils.kt 78.05% <0.00%> (-1.27%) ⬇️
...ndexstatemanagement/IndexStateManagementHistory.kt 80.00% <0.00%> (+1.73%) ⬆️
...anagement/indexstatemanagement/model/Transition.kt 67.69% <0.00%> (+3.07%) ⬆️
...arch/indexmanagement/rollup/RollupSearchService.kt 66.00% <0.00%> (+4.00%) ⬆️
...nt/indexstatemanagement/model/destination/Chime.kt 54.54% <0.00%> (+13.63%) ⬆️

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update a53b049...37b8491. Read the comment docs.

@bowenlan-amzn bowenlan-amzn merged commit c937f07 into opendistro-for-elasticsearch:main Jul 19, 2022
@downsrob downsrob deleted the cve-bump branch July 19, 2022 17:04
downsrob added a commit to downsrob/index-management-odfe that referenced this pull request Jul 22, 2022
bowenlan-amzn pushed a commit that referenced this pull request Jul 22, 2022
)

* Bumps jackson version (#466)

Signed-off-by: Clay Downs <[email protected]>

* Bumps odfe version for patch release (#467)

Signed-off-by: Clay Downs <[email protected]>
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants