Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency com.fasterxml.jackson.core:jackson-databind to v2.13.4 #229

Conversation

mend-for-github-com[bot]
Copy link
Contributor

@mend-for-github-com mend-for-github-com bot commented Oct 5, 2022

This PR contains the following updates:

Package Update Change
com.fasterxml.jackson.core:jackson-databind patch 2.13.3 -> 2.13.4

By merging this PR, the issue #228 will be automatically resolved and closed:

Severity CVSS Score CVE
High High 7.5 CVE-2022-42004

  • If you want to rebase/retry this PR, click this checkbox. ⚠ Warning: custom changes will be lost.

@mend-for-github-com mend-for-github-com bot requested review from a team and madhusudhankonda as code owners October 5, 2022 15:41
@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by WhiteSource label Oct 5, 2022
@@ -133,7 +133,7 @@ dependencies {

val opensearchVersion = "2.1.0"
val jacksonVersion = "2.13.3"
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please also update Jackson version

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@reta this is bot PR :)

Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cr@p :) Thanks @saratvemulapalli , I expected bot somewhere in the name ... :-)

Signed-off-by: Sarat Vemulapalli <vemulapallisarat@gmail.com>
@saratvemulapalli saratvemulapalli requested a review from reta October 5, 2022 16:55
…core-jackson-databind-2.x

Signed-off-by: Sarat Vemulapalli <vemulapallisarat@gmail.com>
@saratvemulapalli saratvemulapalli merged commit 94eb007 into main Oct 5, 2022
@saratvemulapalli saratvemulapalli deleted the whitesource-remediate/com.fasterxml.jackson.core-jackson-databind-2.x branch October 5, 2022 22:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security fix Security fix generated by WhiteSource
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants