Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update jackson-databind to 2.13.2.1 in 2.12.x #9980

Conversation

scala-steward
Copy link
Contributor

Updates com.fasterxml.jackson.core:jackson-databind from 2.13.2 to 2.13.2.1.

I'll automatically update this PR to resolve conflicts as long as you don't change it yourself.

If you'd like to skip this version, you can just close this PR. If you have any feedback, just mention me in the comments below.

Configure Scala Steward for your repository with a .scala-steward.conf file.

Have a fantastic day writing Scala!

Files still referring to the old version number

The following files still refer to the old version number (2.13.2).
You might want to review and update them manually.

build.sbt
Ignore future updates

Add this to your .scala-steward.conf file to ignore future updates of this dependency:

updates.ignore = [ { groupId = "com.fasterxml.jackson.core", artifactId = "jackson-databind" } ]

labels: library-update, old-version-remains, commit-count:1

@scala-jenkins scala-jenkins added this to the 2.12.16 milestone Mar 25, 2022
@SethTisue
Copy link
Member

having trouble finding any release notes for this

there's a bug report at FasterXML/jackson-databind#3428, is all I found

it's puzzling that the Travis-CI build failed (twice) but Jenkins succeeded

in any case, it seems like one we can skip

@SethTisue SethTisue closed this Mar 25, 2022
@SethTisue SethTisue removed this from the 2.12.16 milestone Mar 25, 2022
@pjfanning
Copy link
Contributor

@SethTisue jackson-databind is the only jackson jar published for 2.13.2.1 - other jackson jars need to stay at 2.13.2 - the special jackson-databind release is for https://www.cvedetails.com/cve/CVE-2020-36518/

@SethTisue SethTisue reopened this Mar 26, 2022
@scala-jenkins scala-jenkins added this to the 2.12.16 milestone Mar 26, 2022
@SethTisue SethTisue self-assigned this Mar 26, 2022
@scala-steward
Copy link
Contributor Author

Superseded by #9996.

@scala-steward scala-steward deleted the update/2.12.x/jackson-databind-2.13.2.1 branch April 8, 2022 09:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
4 participants