fix(QTDI-3165): CVE-202654512 bump jackson to 2.21.5 - #1264
Conversation
There was a problem hiding this comment.
Pull request overview
Updates the root Maven dependency version properties to address a reported Jackson CVE by bumping the Jackson versions used across the build.
Changes:
- Bump
jackson-coreandjackson-databindproperties from2.21.2to2.21.5.
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
ozhelezniak-talend
left a comment
There was a problem hiding this comment.
lgtm
but connectors repos on 2.22 already
maybe it's better to align with them if we don't have a limitations? (cloud or smth like that)
In fact, we use the less possible jackson in repo, it's mainly a transitive dep from beam/cloud related features. |

0 New Issues
0 Fixed Issues
0 Accepted Issues
No data about coverage (0.00% Estimated after merge)
Requirements
Why this PR is needed?
What does this PR adds (design/code thoughts)?
AI generated code
https://internal.qlik.dev/general/ways-of-working/code-reviews/#guidelines-for-ai-generated-code