You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@pulsar.apache.org by ni...@apache.org on 2022/10/17 07:06:33 UTC

[pulsar] 02/02: [fix][sec] Upgrade JacksonXML to 2.13.4 (#18020)

This is an automated email from the ASF dual-hosted git repository.

nicoloboschi pushed a commit to branch branch-2.11
in repository https://gitbox.apache.org/repos/asf/pulsar.git

commit 305b73566adf5f828f62110c413927199b9350e5
Author: Nicolò Boschi <bo...@gmail.com>
AuthorDate: Mon Oct 17 09:02:56 2022 +0200

    [fix][sec] Upgrade JacksonXML to 2.13.4 (#18020)
    
    (cherry picked from commit 44215012ae74671674aee8b83c0a4522c309f421)
---
 distribution/server/src/assemble/LICENSE.bin.txt | 16 +++++++-------
 pom.xml                                          |  2 +-
 pulsar-sql/presto-distribution/LICENSE           | 28 ++++++++++++------------
 3 files changed, 23 insertions(+), 23 deletions(-)

diff --git a/distribution/server/src/assemble/LICENSE.bin.txt b/distribution/server/src/assemble/LICENSE.bin.txt
index a96b7559e0d..456e38167ca 100644
--- a/distribution/server/src/assemble/LICENSE.bin.txt
+++ b/distribution/server/src/assemble/LICENSE.bin.txt
@@ -312,14 +312,14 @@ The Apache Software License, Version 2.0
  * JCommander -- com.beust-jcommander-1.82.jar
  * High Performance Primitive Collections for Java -- com.carrotsearch-hppc-0.9.1.jar
  * Jackson
-     - com.fasterxml.jackson.core-jackson-annotations-2.13.3.jar
-     - com.fasterxml.jackson.core-jackson-core-2.13.3.jar
-     - com.fasterxml.jackson.core-jackson-databind-2.13.3.jar
-     - com.fasterxml.jackson.dataformat-jackson-dataformat-yaml-2.13.3.jar
-     - com.fasterxml.jackson.jaxrs-jackson-jaxrs-base-2.13.3.jar
-     - com.fasterxml.jackson.jaxrs-jackson-jaxrs-json-provider-2.13.3.jar
-     - com.fasterxml.jackson.module-jackson-module-jaxb-annotations-2.13.3.jar
-     - com.fasterxml.jackson.module-jackson-module-jsonSchema-2.13.3.jar
+     - com.fasterxml.jackson.core-jackson-annotations-2.13.4.jar
+     - com.fasterxml.jackson.core-jackson-core-2.13.4.jar
+     - com.fasterxml.jackson.core-jackson-databind-2.13.4.jar
+     - com.fasterxml.jackson.dataformat-jackson-dataformat-yaml-2.13.4.jar
+     - com.fasterxml.jackson.jaxrs-jackson-jaxrs-base-2.13.4.jar
+     - com.fasterxml.jackson.jaxrs-jackson-jaxrs-json-provider-2.13.4.jar
+     - com.fasterxml.jackson.module-jackson-module-jaxb-annotations-2.13.4.jar
+     - com.fasterxml.jackson.module-jackson-module-jsonSchema-2.13.4.jar
  * Caffeine -- com.github.ben-manes.caffeine-caffeine-2.9.1.jar
  * Conscrypt -- org.conscrypt-conscrypt-openjdk-uber-2.5.2.jar
  * Proto Google Common Protos -- com.google.api.grpc-proto-google-common-protos-2.0.1.jar
diff --git a/pom.xml b/pom.xml
index d1646558b04..6f4f509b51d 100644
--- a/pom.xml
+++ b/pom.xml
@@ -137,7 +137,7 @@ flexible messaging model and an intuitive client API.</description>
     <log4j2.version>2.18.0</log4j2.version>
     <bouncycastle.version>1.69</bouncycastle.version>
     <bouncycastlefips.version>1.0.2</bouncycastlefips.version>
-    <jackson.version>2.13.3</jackson.version>
+    <jackson.version>2.13.4</jackson.version>
     <reflections.version>0.9.11</reflections.version>
     <swagger.version>1.6.2</swagger.version>
     <puppycrawl.checkstyle.version>8.37</puppycrawl.checkstyle.version>
diff --git a/pulsar-sql/presto-distribution/LICENSE b/pulsar-sql/presto-distribution/LICENSE
index 30ce4412316..58a78247e02 100644
--- a/pulsar-sql/presto-distribution/LICENSE
+++ b/pulsar-sql/presto-distribution/LICENSE
@@ -207,19 +207,19 @@ This projects includes binary packages with the following licenses:
 The Apache Software License, Version 2.0
 
   * Jackson
-    - jackson-annotations-2.13.3.jar
-    - jackson-core-2.13.3.jar
-    - jackson-databind-2.13.3.jar
-    - jackson-dataformat-smile-2.13.3.jar
-    - jackson-datatype-guava-2.13.3.jar
-    - jackson-datatype-jdk8-2.13.3.jar
-    - jackson-datatype-joda-2.13.3.jar
-    - jackson-datatype-jsr310-2.13.3.jar
-    - jackson-dataformat-yaml-2.13.3.jar
-    - jackson-jaxrs-base-2.13.3.jar
-    - jackson-jaxrs-json-provider-2.13.3.jar
-    - jackson-module-jaxb-annotations-2.13.3.jar
-    - jackson-module-jsonSchema-2.13.3.jar
+    - jackson-annotations-2.13.4.jar
+    - jackson-core-2.13.4.jar
+    - jackson-databind-2.13.4.jar
+    - jackson-dataformat-smile-2.13.4.jar
+    - jackson-datatype-guava-2.13.4.jar
+    - jackson-datatype-jdk8-2.13.4.jar
+    - jackson-datatype-joda-2.13.4.jar
+    - jackson-datatype-jsr310-2.13.4.jar
+    - jackson-dataformat-yaml-2.13.4.jar
+    - jackson-jaxrs-base-2.13.4.jar
+    - jackson-jaxrs-json-provider-2.13.4.jar
+    - jackson-module-jaxb-annotations-2.13.4.jar
+    - jackson-module-jsonSchema-2.13.4.jar
  * Guava
     - guava-31.0.1-jre.jar
     - failureaccess-1.0.1.jar
@@ -463,7 +463,7 @@ The Apache Software License, Version 2.0
   * Snappy
     - snappy-java-1.1.8.4.jar
   * Jackson
-    - jackson-module-parameter-names-2.13.3.jar
+    - jackson-module-parameter-names-2.13.4.jar
   * Java Assist
     - javassist-3.25.0-GA.jar
   * Java Native Access