Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update json parser #788

Merged
merged 1 commit into from
Apr 6, 2018
Merged

update json parser #788

merged 1 commit into from
Apr 6, 2018

Conversation

strehle
Copy link
Member

@strehle strehle commented Mar 8, 2018

@cfdreddbot
Copy link

Hey strehle!

Thanks for submitting this pull request! I'm here to inform the recipients of the pull request that you and the commit authors have already signed the CLA.

@cf-gitbot
Copy link

We have created an issue in Pivotal Tracker to manage this:

https://www.pivotaltracker.com/story/show/155819103

The labels on this github issue will be updated when the story is started.

@jhamon
Copy link
Contributor

jhamon commented Mar 8, 2018

@strehle What's the story here? Do you think this change is needed?

@strehle
Copy link
Member Author

strehle commented Mar 8, 2018

Story is the CVE https://nvd.nist.gov/vuln/detail/CVE-2018-7489
and related information from FasterXML/jackson-databind#1931 which means in 2.8.11.1 and 2.9.5 fixed, but UAA uses 2.9.4 and 2.9.5 is not released yet.

@jhamon
Copy link
Contributor

jhamon commented Mar 9, 2018

Ah, 2.9.5 isn't out yet. I was confused about why you closed this PR but now I understand. We will bump when they release a fix.

@cf-gitbot cf-gitbot added accepted Accepted the issue and removed delivered labels Mar 9, 2018
@strehle strehle reopened this Apr 1, 2018
@cfdreddbot
Copy link

Hey strehle!

Thanks for submitting this pull request! I'm here to inform the recipients of the pull request that you and the commit authors have already signed the CLA.

@cf-gitbot
Copy link

We have created an issue in Pivotal Tracker to manage this:

https://www.pivotaltracker.com/story/show/156423446

The labels on this github issue will be updated when the story is started.

@cf-gitbot cf-gitbot added unscheduled and removed accepted Accepted the issue labels Apr 1, 2018
@strehle
Copy link
Member Author

strehle commented Apr 1, 2018

hi @jhamon , update available, therefore please use it for next version

@tack-sap tack-sap merged commit c50be9e into cloudfoundry:develop Apr 6, 2018
@cf-gitbot cf-gitbot added delivered accepted Accepted the issue and removed scheduled delivered labels Apr 6, 2018
@strehle strehle deleted the patch-1 branch June 15, 2018 08:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
accepted Accepted the issue
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants