Skip to content

Conversation

@pen4
Copy link

@pen4 pen4 commented Nov 19, 2022

What happened?

There are 1 security vulnerabilities found in com.fasterxml.jackson.core:jackson-databind 2.13.4.2

What did I do?

Upgrade com.fasterxml.jackson.core:jackson-databind from 2.13.4.2 to 2.14.0-rc1 for vulnerability fix

What did you expect to happen?

Ideally, no insecure libs should be used.

The specification of the pull request

PR Specification from OSCS

@sutra
Copy link
Collaborator

sutra commented Nov 20, 2022

Additional fix version in 2.13.4.1 and 2.12.17.1, so the version 2.13.4.2 we are using, does not affect.

@sutra sutra closed this Nov 20, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

2 participants