Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

(build) Upgrade json-smart dependency to 2.4.9 #7788

Merged
merged 1 commit into from
Apr 11, 2023
Merged

Conversation

iprentic
Copy link
Contributor

Upgrade to version without stack overflow vulnerability: https://research.jfrog.com/vulnerabilities/stack-exhaustion-in-json-smart-leads-to-denial-of-service-when-parsing-malformed-json-xray-427633/

Checklist

  • The PR conforms to DataHub's Contributing Guideline (particularly Commit Message Format)
  • Links to related issues (if applicable)
  • Tests for the changes have been added/updated (if applicable)
  • Docs related to the changes have been added/updated (if applicable). If a new feature has been added a Usage Guide has been added for the same.
  • For any breaking change/potential downtime/deprecation/big changes an entry has been made in Updating DataHub

Copy link
Contributor

@meyerkev meyerkev left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@iprentic iprentic merged commit 77c5e8d into master Apr 11, 2023
@iprentic iprentic deleted the json-smart-dep branch April 11, 2023 16:55
yoonhyejin pushed a commit that referenced this pull request Apr 19, 2023
Co-authored-by: Indy Prentice <indy@Indys-MacBook-Pro.local>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants