You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@tika.apache.org by ta...@apache.org on 2022/11/01 18:51:04 UTC

[tika] branch main updated: TIKA-3869 -- update jackson databind version

This is an automated email from the ASF dual-hosted git repository.

tallison pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/tika.git


The following commit(s) were added to refs/heads/main by this push:
     new e1d9bcd9a TIKA-3869 -- update jackson databind version
e1d9bcd9a is described below

commit e1d9bcd9ae75999078df616c61874cac0a0165e5
Author: tballison <ta...@apache.org>
AuthorDate: Tue Nov 1 14:50:54 2022 -0400

    TIKA-3869 -- update jackson databind version
---
 tika-parent/pom.xml                                            | 10 ++--------
 .../tika-parser-cad-module/pom.xml                             |  5 +----
 2 files changed, 3 insertions(+), 12 deletions(-)

diff --git a/tika-parent/pom.xml b/tika-parent/pom.xml
index e42c26924..7aad1a3e4 100644
--- a/tika-parent/pom.xml
+++ b/tika-parent/pom.xml
@@ -330,6 +330,7 @@
     <jackcess.encrypt.version>4.0.1</jackcess.encrypt.version>
     <jackrabbit.version>2.21.13</jackrabbit.version>
     <jackson.version>2.13.4</jackson.version>
+    <jackson.databind.version>2.13.4.2</jackson.databind.version>
     <javax.annotation.version>1.3.2</javax.annotation.version>
     <javax.jcr.version>2.0</javax.jcr.version>
     <javax.rest.version>2.1.1</javax.rest.version>
@@ -437,7 +438,7 @@
       <dependency>
         <groupId>com.fasterxml.jackson.core</groupId>
         <artifactId>jackson-databind</artifactId>
-        <version>${jackson.version}</version>
+        <version>${jackson.databind.version}</version>
       </dependency>
       <dependency>
         <groupId>com.fasterxml.jackson.datatype</groupId>
@@ -881,13 +882,6 @@
                 <artifactId>h2</artifactId>
                 <version>2.1.214</version>
             </exclude>
-            <!-- I don't think this affects us based on this description: https://nvd.nist.gov/vuln/detail/CVE-2022-42003.
-            A stable release is not yet available to fix this -->
-            <exclude>
-              <groupId>com.fasterxml.jackson.core</groupId>
-              <artifactId>jackson-databind</artifactId>
-              <version>2.13.4</version>
-            </exclude>
           </excludeCoordinates>
           <fail>true</fail>
         </configuration>
diff --git a/tika-parsers/tika-parsers-standard/tika-parsers-standard-modules/tika-parser-cad-module/pom.xml b/tika-parsers/tika-parsers-standard/tika-parsers-standard-modules/tika-parser-cad-module/pom.xml
index c08ebeeee..5588afa8e 100644
--- a/tika-parsers/tika-parsers-standard/tika-parsers-standard-modules/tika-parser-cad-module/pom.xml
+++ b/tika-parsers/tika-parsers-standard/tika-parsers-standard-modules/tika-parser-cad-module/pom.xml
@@ -36,16 +36,13 @@
       <artifactId>tika-parser-microsoft-module</artifactId>
       <version>${project.version}</version>
     </dependency>
-
     <dependency>
     	<groupId>com.fasterxml.jackson.core</groupId>
     	<artifactId>jackson-core</artifactId>
-	    <version>${jackson.version}</version><!--$NO-MVN-MAN-VER$-->
     </dependency>
-        <dependency>
+    <dependency>
     	<groupId>com.fasterxml.jackson.core</groupId>
     	<artifactId>jackson-databind</artifactId>
-	    <version>${jackson.version}</version><!--$NO-MVN-MAN-VER$-->
     </dependency>
   </dependencies>
   <build>