Skip to content
This repository has been archived by the owner on Mar 21, 2022. It is now read-only.

Upgrade jackson deps to from 2.9.6 to latest 2.9.8 #1132

Merged
merged 1 commit into from
Jan 15, 2019

Conversation

davidxia
Copy link
Contributor

This patches a vulnerability in jackson-databind

Upgrade the other jackson deps to the same latest version for consistency.

This patches a vulnerability in jackson-databind

* CVE-2018-19360
* CVE-2018-19362
* CVE-2018-19361
* CVE-2018-14718
* CVE-2018-14721
* CVE-2018-14719
* CVE-2018-14720

Upgrade the other jackson deps to the same latest version for consistency.
@davidxia davidxia requested a review from a team January 15, 2019 18:34
@codecov
Copy link

codecov bot commented Jan 15, 2019

Codecov Report

Merging #1132 into master will decrease coverage by 0.1%.
The diff coverage is n/a.

@@             Coverage Diff              @@
##             master    #1132      +/-   ##
============================================
- Coverage     68.12%   68.02%   -0.11%     
+ Complexity      797      796       -1     
============================================
  Files           181      181              
  Lines          3909     3909              
  Branches        410      410              
============================================
- Hits           2663     2659       -4     
- Misses         1077     1079       +2     
- Partials        169      171       +2

@mattnworb
Copy link
Member

👍

maybe we can bundle this and #1131 into the same release

@davidxia
Copy link
Contributor Author

sounds good

@davidxia davidxia merged commit 7713866 into master Jan 15, 2019
@davidxia davidxia deleted the dxia/upgrade-jackson branch January 15, 2019 19:34
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants