Skip to content

fix(QTDI-3165): CVE-202654512 bump jackson to 2.21.5 - #1264

Merged
undx merged 1 commit into
masterfrom
undx/QTDI-3165-CVE-2026-54512-databind
Aug 20, 2026
Merged

undx merged 1 commit into
masterfrom
undx/QTDI-3165-CVE-2026-54512-databind

Conversation

@undx

@undx undx commented Aug 18, 2026

Copy link
Copy Markdown
Member

Requirements

  • Any code change adding any logic MUST be tested through a unit test executed with the default build
  • Any API addition MUST be done with a documentation update if relevant

Why this PR is needed?

What does this PR adds (design/code thoughts)?

AI generated code

https://internal.qlik.dev/general/ways-of-working/code-reviews/#guidelines-for-ai-generated-code

  • [] this PR has been written with the help of GitHub Copilot or another generative AI tool

@undx
undx requested review from ozhelezniak-talend and a lite review from Copilot August 18, 2026 08:02

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the root Maven dependency version properties to address a reported Jackson CVE by bumping the Jackson versions used across the build.

Changes:

  • Bump jackson-core and jackson-databind properties from 2.21.2 to 2.21.5.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread pom.xml
@sonar-rnd

sonar-rnd Bot commented Aug 18, 2026

Copy link
Copy Markdown

@ozhelezniak-talend ozhelezniak-talend left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm
but connectors repos on 2.22 already
maybe it's better to align with them if we don't have a limitations? (cloud or smth like that)

@undx

undx commented Aug 19, 2026

Copy link
Copy Markdown
Member Author

lgtm but connectors repos on 2.22 already maybe it's better to align with them if we don't have a limitations? (cloud or smth like that)

In fact, we use the less possible jackson in repo, it's mainly a transitive dep from beam/cloud related features.
There's no direct use in framework itself...

@undx
undx merged commit 490b168 into master Aug 20, 2026
11 of 12 checks passed
@undx
undx deleted the undx/QTDI-3165-CVE-2026-54512-databind branch August 20, 2026 06:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants