You are viewing a plain text version of this content. The canonical link for it is here.
Posted to github@arrow.apache.org by "lidavidm (via GitHub)" <gi...@apache.org> on 2023/05/25 20:05:08 UTC
[GitHub] [arrow] lidavidm commented on issue #35771: CVE-2022-42003
lidavidm commented on issue #35771:
URL: https://github.com/apache/arrow/issues/35771#issuecomment-1563443218
No, we should be fine upgrading immediately (and you should be fine forcing Maven to resolve a newer version)
@davisusanibar can you bump this?
And I vaguely recall that Jackson is there for testing (to load the integration test files), in which case we should see about eliminating it as a dependency (in anything we ship)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: github-unsubscribe@arrow.apache.org
For queries about this service, please contact Infrastructure at:
users@infra.apache.org