Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ST-3988: Update jackson version to 2.10.5 #274

Merged
merged 3 commits into from Jul 22, 2020
Merged

Conversation

niteshmor
Copy link
Contributor

For jackson version 2.10.2, jackson-dataformat-yaml brings in snakeyaml v1.24, which is supposedly affected by CVE-2017-18640

For jackson version 2.10.2, `jackson-dataformat-yaml` brings in snakeyaml v1.24, which is supposedly affected by CVE-2017-18640
@niteshmor
Copy link
Contributor Author

The pull request is against 5.4.x for 2.10.2=>2.10.4, which is only a patch update.
5.3.x is on version 2.9.10, and going from 2.9 to 2.10 will require a bit more consideration.

@niteshmor niteshmor requested a review from a team July 22, 2020 16:50
@niteshmor
Copy link
Contributor Author

@confluentinc/tools separate pull requests to kafka will be required to make this change across the board.

Copy link
Contributor

@ewencp ewencp left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It looks like there's a 2.10.5 as of a day or two ago, probably makes sense to update to that now instead.

@niteshmor
Copy link
Contributor Author

@ewencp good catch. Thanks. Updated.

@niteshmor niteshmor requested review from ewencp and a team July 22, 2020 18:21
@niteshmor niteshmor merged commit bf51d98 into 5.4.x Jul 22, 2020
@niteshmor niteshmor deleted the niteshmor-jackson-upgrade branch July 22, 2020 21:15
@niteshmor
Copy link
Contributor Author

Looks like this didn't get applied to 5.5.x and above :(
I thought I did a pint merge. Doing a manual cherry pick

@kkonstantine kkonstantine changed the title ST-3988: Update jackson version to 2.10.4 ST-3988: Update jackson version to 2.10.5 Jul 24, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants