Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Shaded JAR contains outdated Jackson #85

Closed
ksobolew opened this issue Apr 11, 2023 · 1 comment
Closed

Shaded JAR contains outdated Jackson #85

ksobolew opened this issue Apr 11, 2023 · 1 comment

Comments

@ksobolew
Copy link

The shaded JAR of linkedin's calcite-core contains several Jackson libraries at versions 2.13.2, which is relatively new (but still has some CVE's atached to it), and jackson-databind 2.9.10.8, which is pretty old at this point. Since this is a shaded JAR, we who depend on this library can't force a newer version of Jackson without re-forking the library and rebuilding the JAR, so hereby I'm asking to bump the version of Jackson. Thanks!

@aastha25
Copy link
Contributor

Thanks @ksobolew for bringing it up. I have created a PR #89 for the upgrade. It should be checked in soon.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants