Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fixed JENKINS-59379: Update jackson via BOM import #427

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

msymons
Copy link

@msymons msymons commented Sep 15, 2019

  • Change property name from jackson-databind.version to jackson.version
  • Replace jackson modules in dependencyManagement by jackson-bom POM import
  • Use version 2.9.9.20190807. This gives jackson-databind 2.9.9.3 with fixes for four CVE

* Change property name from jackson-databind.version to jackson.version
* Replace jackson modules in dependencyManagement by jackson-bom POM import
* Use version 2.9.9.20190807.  This gives jackson-databind 2.9.9.3 with fixes for four CVE
@khmarbaise khmarbaise self-requested a review September 16, 2019 20:03
@khmarbaise khmarbaise added Dependency Upgrade Upgraded dependency security Possible security findings labels Sep 16, 2019
@khmarbaise khmarbaise added this to the Release 0.4.0 milestone Sep 16, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Dependency Upgrade Upgraded dependency security Possible security findings
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants