Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Conversation

@msymons
Copy link

@msymons msymons commented Sep 15, 2019

  • Change property name from jackson-databind.version to jackson.version
  • Replace jackson modules in dependencyManagement by jackson-bom POM import
  • Use version 2.9.9.20190807. This gives jackson-databind 2.9.9.3 with fixes for four CVE

* Change property name from jackson-databind.version to jackson.version
* Replace jackson modules in dependencyManagement by jackson-bom POM import
* Use version 2.9.9.20190807.  This gives jackson-databind 2.9.9.3 with fixes for four CVE
@khmarbaise khmarbaise self-requested a review September 16, 2019 20:03
@khmarbaise khmarbaise added Dependency Upgrade Upgraded dependency security Possible security findings labels Sep 16, 2019
@khmarbaise khmarbaise added this to the Release 0.4.0 milestone Sep 16, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Dependency Upgrade Upgraded dependency security Possible security findings

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

Morty Proxy This is a proxified and sanitized view of the page, visit original site.