Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
This PR updates com.fasterxml.jackson and org.codehaus.jackson core libraries versions in the pom.xml file to address known vulnerabilities and improve the overall security of the project.
Updated Libraries
com.fasterxml.jackson
2.12.7.20221012
->2.12.7.20240502
Addresses the following vulnerabilities:
org.codehaus.jackson:
1.9.13
->1.9.14.jdk17-redhat-00001
Addresses several known vulnerabilities, including:
Additionally, a new repository (Red Hat GA Repository) has been added to the pom.xml file to support org.codehaus.jackson library update.
Although this PR points to version 30.0.0, and the 30.0.0 CI workflow is not fully functional in our environment, I successfully tested the updated libraries by applying the same changes to the master branch.
Key changed/added classes in this PR
N/A (Only
pom.xml
was modified)Release note
Updated com.fasterxml.jackson and org.codehaus.jackson libraries to address multiple security vulnerabilities, including potential denial of service and remote code execution vulnerabilities.
This PR has:
added integration tests.