Skip to content

Commit

Permalink
[Security] Upgrade Jackson to 2.12.6
Browse files Browse the repository at this point in the history
(cherry picked from commit f8a9159)
  • Loading branch information
nicoloboschi committed Jan 11, 2022
1 parent 71253df commit c28ad1f
Show file tree
Hide file tree
Showing 4 changed files with 26 additions and 26 deletions.
16 changes: 8 additions & 8 deletions distribution/server/src/assemble/LICENSE.bin.txt
Original file line number Diff line number Diff line change
Expand Up @@ -312,14 +312,14 @@ The Apache Software License, Version 2.0
* JCommander -- com.beust-jcommander-1.78.jar
* High Performance Primitive Collections for Java -- com.carrotsearch-hppc-0.7.3.jar
* Jackson
- com.fasterxml.jackson.core-jackson-annotations-2.11.1.jar
- com.fasterxml.jackson.core-jackson-core-2.11.1.jar
- com.fasterxml.jackson.core-jackson-databind-2.11.1.jar
- com.fasterxml.jackson.dataformat-jackson-dataformat-yaml-2.11.1.jar
- com.fasterxml.jackson.jaxrs-jackson-jaxrs-base-2.11.1.jar
- com.fasterxml.jackson.jaxrs-jackson-jaxrs-json-provider-2.11.1.jar
- com.fasterxml.jackson.module-jackson-module-jaxb-annotations-2.11.1.jar
- com.fasterxml.jackson.module-jackson-module-jsonSchema-2.11.1.jar
- com.fasterxml.jackson.core-jackson-annotations-2.12.6.jar
- com.fasterxml.jackson.core-jackson-core-2.12.6.jar
- com.fasterxml.jackson.core-jackson-databind-2.12.6.jar
- com.fasterxml.jackson.dataformat-jackson-dataformat-yaml-2.12.6.jar
- com.fasterxml.jackson.jaxrs-jackson-jaxrs-base-2.12.6.jar
- com.fasterxml.jackson.jaxrs-jackson-jaxrs-json-provider-2.12.6.jar
- com.fasterxml.jackson.module-jackson-module-jaxb-annotations-2.12.6.jar
- com.fasterxml.jackson.module-jackson-module-jsonSchema-2.12.6.jar
- org.codehaus.jackson-jackson-core-asl-1.9.11.jar
- org.codehaus.jackson-jackson-mapper-asl-1.9.11.jar
* Caffeine -- com.github.ben-manes.caffeine-caffeine-2.6.2.jar
Expand Down
4 changes: 2 additions & 2 deletions pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -120,8 +120,8 @@ flexible messaging model and an intuitive client API.</description>
<log4j2.version>2.17.1</log4j2.version>
<bouncycastle.version>1.68</bouncycastle.version>
<bouncycastlefips.version>1.0.2</bouncycastlefips.version>
<jackson.version>2.11.1</jackson.version>
<jackson.databind.version>2.11.1</jackson.databind.version>
<jackson.version>2.12.6</jackson.version>
<jackson.databind.version>2.12.6</jackson.databind.version>
<reflections.version>0.9.11</reflections.version>
<swagger.version>1.5.21</swagger.version>
<puppycrawl.checkstyle.version>8.37</puppycrawl.checkstyle.version>
Expand Down
28 changes: 14 additions & 14 deletions pulsar-sql/presto-distribution/LICENSE
Original file line number Diff line number Diff line change
Expand Up @@ -207,19 +207,19 @@ This projects includes binary packages with the following licenses:
The Apache Software License, Version 2.0

* Jackson
- jackson-annotations-2.11.1.jar
- jackson-core-2.11.1.jar
- jackson-databind-2.11.1.jar
- jackson-dataformat-smile-2.11.1.jar
- jackson-datatype-guava-2.11.1.jar
- jackson-datatype-jdk8-2.11.1.jar
- jackson-datatype-joda-2.11.1.jar
- jackson-datatype-jsr310-2.11.1.jar
- jackson-dataformat-yaml-2.11.1.jar
- jackson-jaxrs-base-2.11.1.jar
- jackson-jaxrs-json-provider-2.11.1.jar
- jackson-module-jaxb-annotations-2.11.1.jar
- jackson-module-jsonSchema-2.11.1.jar
- jackson-annotations-2.12.6.jar
- jackson-core-2.12.6.jar
- jackson-databind-2.12.6.jar
- jackson-dataformat-smile-2.12.6.jar
- jackson-datatype-guava-2.12.6.jar
- jackson-datatype-jdk8-2.12.6.jar
- jackson-datatype-joda-2.12.6.jar
- jackson-datatype-jsr310-2.12.6.jar
- jackson-dataformat-yaml-2.12.6.jar
- jackson-jaxrs-base-2.12.6.jar
- jackson-jaxrs-json-provider-2.12.6.jar
- jackson-module-jaxb-annotations-2.12.6.jar
- jackson-module-jsonSchema-2.12.6.jar
* Guava
- guava-30.1-jre.jar
- failureaccess-1.0.1.jar
Expand Down Expand Up @@ -444,7 +444,7 @@ The Apache Software License, Version 2.0
- gson-2.8.9.jar
* Jackson
- jackson-module-parameter-names-2.10.3.jar
- jackson-module-parameter-names-2.11.1.jar
- jackson-module-parameter-names-2.12.6.jar
* Java Assist
- javassist-3.25.0-GA.jar
* Jetty
Expand Down
4 changes: 2 additions & 2 deletions pulsar-sql/presto-distribution/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -44,10 +44,10 @@
<!-- Launcher properties -->
<main-class>io.prestosql.server.PrestoServer</main-class>
<process-name>${project.artifactId}</process-name>
<jackson.version>2.11.1</jackson.version>
<jackson.version>2.12.6</jackson.version>
<!--fix Security Vulnerabilities-->
<!--https://www.cvedetails.com/vulnerability-list/vendor_id-15866/product_id-42991/Fasterxml-Jackson-databind.html-->
<jackson.databind.version>2.11.1</jackson.databind.version>
<jackson.databind.version>2.12.6</jackson.databind.version>
<maven.version>3.0.5</maven.version>
<guava.version>30.1-jre</guava.version>
<asynchttpclient.version>2.12.1</asynchttpclient.version>
Expand Down

0 comments on commit c28ad1f

Please sign in to comment.