-
Notifications
You must be signed in to change notification settings - Fork 7.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
ZOOKEEPER-3751: upgrade jackson-databind to 2.10 from 2.9 #1341
Conversation
The original PR (apache#1283) was only merged to 3.6+, as in 3.5 we also have to change the ant configs. I created a new PR to kick-in the CI also for branch 3.5.
I executed the admin server related unit tests and also tested manually the admin server with Chrome and with curl. Everything seemed to be fine. |
applying this patch on branch-3.5 makes "mvn clean package -DskipTests dependency-check:check" to run successfully |
retest ant build |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
merging as soon as ANT build is green
retest ant build |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
FWIW, 2.11.0 was just released.
We only upgrade this to fix some CVEs on branch-3.5. I am not familiar with jackson, but maybe a more mature 2.10.3 is safer in terms of future CVEs than the first 2.11 release would be. But I am happy to do an other upgrade later, if it would be needed. I'll merge this PR now to branch 3.5. |
The original PR (#1283) was only merged to 3.6+ as in 3.5 we also have to change the ant configs. I created a new PR to kick-in the CI also for branch 3.5. Author: Mate Szalay-Beko <symat@apache.org> Reviewers: Enrico Olivelli <eolivelli@apache.org> Closes #1341 from symat/ZOOKEEPER-3751-branch-3.5
The original PR (#1283) was only merged to 3.6+ as in 3.5 we also have to change the ant configs. I created a new PR to kick-in the CI also for branch 3.5.