Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SPARK-39250][BUILD] Upgrade Jackson to 2.13.3 #36627

Closed
wants to merge 1 commit into from
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 7 additions & 7 deletions dev/deps/spark-deps-hadoop-2-hive-2.3
Original file line number Diff line number Diff line change
Expand Up @@ -112,16 +112,16 @@ httpclient/4.5.13//httpclient-4.5.13.jar
httpcore/4.4.14//httpcore-4.4.14.jar
istack-commons-runtime/3.0.8//istack-commons-runtime-3.0.8.jar
ivy/2.5.0//ivy-2.5.0.jar
jackson-annotations/2.13.2//jackson-annotations-2.13.2.jar
jackson-annotations/2.13.3//jackson-annotations-2.13.3.jar
jackson-core-asl/1.9.13//jackson-core-asl-1.9.13.jar
jackson-core/2.13.2//jackson-core-2.13.2.jar
jackson-databind/2.13.2.1//jackson-databind-2.13.2.1.jar
jackson-dataformat-cbor/2.13.2//jackson-dataformat-cbor-2.13.2.jar
jackson-dataformat-yaml/2.13.2//jackson-dataformat-yaml-2.13.2.jar
jackson-datatype-jsr310/2.13.2//jackson-datatype-jsr310-2.13.2.jar
jackson-core/2.13.3//jackson-core-2.13.3.jar
jackson-databind/2.13.3//jackson-databind-2.13.3.jar
jackson-dataformat-cbor/2.13.3//jackson-dataformat-cbor-2.13.3.jar
jackson-dataformat-yaml/2.13.3//jackson-dataformat-yaml-2.13.3.jar
jackson-datatype-jsr310/2.13.3//jackson-datatype-jsr310-2.13.3.jar
jackson-jaxrs/1.9.13//jackson-jaxrs-1.9.13.jar
jackson-mapper-asl/1.9.13//jackson-mapper-asl-1.9.13.jar
jackson-module-scala_2.12/2.13.2//jackson-module-scala_2.12-2.13.2.jar
jackson-module-scala_2.12/2.13.3//jackson-module-scala_2.12-2.13.3.jar
jackson-xc/1.9.13//jackson-xc-1.9.13.jar
jakarta.annotation-api/1.3.5//jakarta.annotation-api-1.3.5.jar
jakarta.inject/2.6.1//jakarta.inject-2.6.1.jar
Expand Down
14 changes: 7 additions & 7 deletions dev/deps/spark-deps-hadoop-3-hive-2.3
Original file line number Diff line number Diff line change
Expand Up @@ -102,15 +102,15 @@ httpcore/4.4.14//httpcore-4.4.14.jar
ini4j/0.5.4//ini4j-0.5.4.jar
istack-commons-runtime/3.0.8//istack-commons-runtime-3.0.8.jar
ivy/2.5.0//ivy-2.5.0.jar
jackson-annotations/2.13.2//jackson-annotations-2.13.2.jar
jackson-annotations/2.13.3//jackson-annotations-2.13.3.jar
jackson-core-asl/1.9.13//jackson-core-asl-1.9.13.jar
jackson-core/2.13.2//jackson-core-2.13.2.jar
jackson-databind/2.13.2.1//jackson-databind-2.13.2.1.jar
jackson-dataformat-cbor/2.13.2//jackson-dataformat-cbor-2.13.2.jar
jackson-dataformat-yaml/2.13.2//jackson-dataformat-yaml-2.13.2.jar
jackson-datatype-jsr310/2.13.2//jackson-datatype-jsr310-2.13.2.jar
jackson-core/2.13.3//jackson-core-2.13.3.jar
jackson-databind/2.13.3//jackson-databind-2.13.3.jar
jackson-dataformat-cbor/2.13.3//jackson-dataformat-cbor-2.13.3.jar
jackson-dataformat-yaml/2.13.3//jackson-dataformat-yaml-2.13.3.jar
jackson-datatype-jsr310/2.13.3//jackson-datatype-jsr310-2.13.3.jar
jackson-mapper-asl/1.9.13//jackson-mapper-asl-1.9.13.jar
jackson-module-scala_2.12/2.13.2//jackson-module-scala_2.12-2.13.2.jar
jackson-module-scala_2.12/2.13.3//jackson-module-scala_2.12-2.13.3.jar
jakarta.annotation-api/1.3.5//jakarta.annotation-api-1.3.5.jar
jakarta.inject/2.6.1//jakarta.inject-2.6.1.jar
jakarta.servlet-api/4.0.3//jakarta.servlet-api-4.0.3.jar
Expand Down
4 changes: 2 additions & 2 deletions pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -170,8 +170,8 @@
<!-- for now, not running scalafmt as part of default verify pipeline -->
<scalafmt.skip>true</scalafmt.skip>
<codehaus.jackson.version>1.9.13</codehaus.jackson.version>
<fasterxml.jackson.version>2.13.2</fasterxml.jackson.version>
<fasterxml.jackson.databind.version>2.13.2.1</fasterxml.jackson.databind.version>
<fasterxml.jackson.version>2.13.3</fasterxml.jackson.version>
<fasterxml.jackson.databind.version>2.13.3</fasterxml.jackson.databind.version>
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I add this property because of SPARK-38665, and it can be removed because all jackson jars share same version again.

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If you look at the history, SPARK-38665 is not the only one did that. databind is frequently separated and merged back repeatedly. :) That's the reason why I decided not to remote that property back in this PR.

[SPARK-38665][BUILD] Upgrade jackson due to CVE-2020-36518
[SPARK-33695][BUILD] Upgrade to jackson to 2.10.5 and jackson-databind to 2.10.5.1
[SPARK-28728][BUILD] Bump Jackson Databind to 2.9.9.3

<snappy.version>1.1.8.4</snappy.version>
<netlib.java.version>1.1.2</netlib.java.version>
<netlib.ludovic.dev.version>2.2.1</netlib.ludovic.dev.version>
Expand Down