Skip to content

Commit 7580307

Browse files
belieferwenfang
authored andcommitted
[BUILD] Bump fasterxml.jackson from 2.9.10 to 2.10.0
What changes were proposed in this pull request? The current code uses com.fasterxml.jackson.core:jackson-databind:jar:2.9.10 and it will cause a security vulnerabilities. We referenced GHSA-mx7p-6679-8g3q This Alert remind to upgrate the version of jackson-databind to 2.9.10.1 or later. I referenced Spark 3.0.0 contains jackson-databind:jar:2.10.0.
1 parent d25e615 commit 7580307

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

pom.xml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -138,8 +138,8 @@
138138
<scala.version>2.11.12</scala.version>
139139
<scala.binary.version>2.11</scala.binary.version>
140140
<codehaus.jackson.version>1.9.13</codehaus.jackson.version>
141-
<fasterxml.jackson.version>2.9.10</fasterxml.jackson.version>
142-
<fasterxml.jackson.databind.version>2.9.10</fasterxml.jackson.databind.version>
141+
<fasterxml.jackson.version>2.10.0</fasterxml.jackson.version>
142+
<fasterxml.jackson.databind.version>2.10.0</fasterxml.jackson.databind.version>
143143
<snappy.version>1.1.7.3</snappy.version>
144144
<netlib.java.version>1.1.2</netlib.java.version>
145145
<calcite.version>1.2.0-incubating</calcite.version>

0 commit comments

Comments
 (0)