Skip to content

deps: bump jackson to 2.15.1 #17406

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
May 18, 2023
Merged

deps: bump jackson to 2.15.1 #17406

merged 1 commit into from
May 18, 2023

Conversation

ckipp01
Copy link
Member

@ckipp01 ckipp01 commented May 4, 2023

If you're curious the release notes for this version can be found in
https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.15.

The main reason for this change is that there are some CVEs attatched
to the 2.13.x series that are first fixed in later versions. You can see the
CVEs in the Security tab here on GitHub.

@pjfanning
Copy link
Contributor

Might be better to wait for v2.15.1. There are some large changes in v2.15 and a few issues being reported.

v2.14.3 has many of the security fixes - if you'd prefer to upgrade now but avoid waiting for v2.15.1

@ckipp01
Copy link
Member Author

ckipp01 commented May 8, 2023

Might be better to wait for v2.15.1. There are some large changes in v2.15 and a few issues being reported.

Sure, but I'm assuming 2.15 also fixes a handful of things still in 2.14. Unless there is something specific we want to avoid in 2.15, I don't think there's a reason to block the upgrade.

@mbovel mbovel requested a review from Kordyjan May 8, 2023 12:08
@dram
Copy link

dram commented May 17, 2023

Jackson 2.15.1 has been released. https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.15.1

If you're curious the release notes for this version can be found in
https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.15.
@ckipp01 ckipp01 changed the title deps: bump jackson to 2.15.0 deps: bump jackson to 2.15.1 May 18, 2023
@ckipp01
Copy link
Member Author

ckipp01 commented May 18, 2023

Jackson 2.15.1 has been released. https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.15.1

Thanks for the heads up! I've gone ahead and bumped this.

@Kordyjan Kordyjan merged commit 4ffe5af into scala:main May 18, 2023
@ckipp01 ckipp01 deleted the jacksonBump branch May 18, 2023 11:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants