You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@pulsar.apache.org by GitBox <gi...@apache.org> on 2020/07/12 16:16:57 UTC

[GitHub] [pulsar] merlimat opened a new pull request #7519: Update Jackson to 2.11.1 and ensure all dependencies are pinned

merlimat opened a new pull request #7519:
URL: https://github.com/apache/pulsar/pull/7519


   ### Motivation
   
   There are several CVEs opened on earlier versions of Jackson, updating to latest stable.
   
   Additionally, we are not pinning the version on all the transitive dependencies and thus picking older versions for them.


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [pulsar] wolfstudy commented on pull request #7519: Update Jackson to 2.11.1 and ensure all dependencies are pinned

Posted by GitBox <gi...@apache.org>.
wolfstudy commented on pull request #7519:
URL: https://github.com/apache/pulsar/pull/7519#issuecomment-665679929


   I will cherry-pick the change to 2.6.1, because the version of jackson we used in the 2.6.1 code is 2.11.1
   
   


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



[GitHub] [pulsar] merlimat merged pull request #7519: Update Jackson to 2.11.1 and ensure all dependencies are pinned

Posted by GitBox <gi...@apache.org>.
merlimat merged pull request #7519:
URL: https://github.com/apache/pulsar/pull/7519


   


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org