You are viewing a plain text version of this content. The canonical link for it is here.
Posted to notifications@geode.apache.org by "mhansonp (GitHub)" <gi...@apache.org> on 2019/09/30 17:44:47 UTC

[GitHub] [geode] mhansonp opened pull request #4102: Fix for GEODE-7255: Pickup Jackson CVE fix

Need to pick up a fix for a CVE in Jackson. Hence rolling the version...

[ Full content available at: https://github.com/apache/geode/pull/4102 ]
This message was relayed via gitbox.apache.org for notifications@geode.apache.org

[GitHub] [geode] mhansonp commented on issue #4102: Fix for GEODE-7255: Pickup Jackson CVE fix

Posted by "mhansonp (GitHub)" <gi...@apache.org>.
Squashed to force a new commit.

[ Full content available at: https://github.com/apache/geode/pull/4102 ]
This message was relayed via gitbox.apache.org for notifications@geode.apache.org

[GitHub] [geode] jmelchio commented on issue #4102: Fix for GEODE-7255: Pickup Jackson CVE fix

Posted by "jmelchio (GitHub)" <gi...@apache.org>.
This should also resolve `CVE-2019-12814` and `CVE-2019-12384` from `GEODE-7264`

[ Full content available at: https://github.com/apache/geode/pull/4102 ]
This message was relayed via gitbox.apache.org for notifications@geode.apache.org

[GitHub] [geode] jmelchio commented on issue #4102: Fix for GEODE-7255: Pickup Jackson CVE fix

Posted by "jmelchio (GitHub)" <gi...@apache.org>.
You need to make sure that the files `assembly-context.txt` and `dependency-classpath.txt` in `geode-assembly/src/integrationTest/resources` are updated with the new version as well. 

[ Full content available at: https://github.com/apache/geode/pull/4102 ]
This message was relayed via gitbox.apache.org for notifications@geode.apache.org