You are viewing a plain text version of this content. The canonical link for it is here.
Posted to github@arrow.apache.org by "lidavidm (via GitHub)" <gi...@apache.org> on 2023/05/25 20:05:08 UTC

[GitHub] [arrow] lidavidm commented on issue #35771: CVE-2022-42003

lidavidm commented on issue #35771:
URL: https://github.com/apache/arrow/issues/35771#issuecomment-1563443218

   No, we should be fine upgrading immediately (and you should be fine forcing Maven to resolve a newer version)
   
   @davisusanibar can you bump this? 
   
   And I vaguely recall that Jackson is there for testing (to load the integration test files), in which case we should see about eliminating it as a dependency (in anything we ship)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: github-unsubscribe@arrow.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org