File tree Expand file tree Collapse file tree 2 files changed +8
-3
lines changed Expand file tree Collapse file tree 2 files changed +8
-3
lines changed Original file line number Diff line number Diff line change 6950
6950
"old": "method <T> com.datastax.oss.driver.api.core.type.reflect.GenericType<com.datastax.oss.driver.api.core.data.CqlVector<T>> com.datastax.oss.driver.api.core.type.reflect.GenericType<T>::vectorOf(com.datastax.oss.driver.api.core.type.reflect.GenericType<T>)",
6951
6951
"new": "method <T extends java.lang.Number> com.datastax.oss.driver.api.core.type.reflect.GenericType<com.datastax.oss.driver.api.core.data.CqlVector<T>> com.datastax.oss.driver.api.core.type.reflect.GenericType<T>::vectorOf(com.datastax.oss.driver.api.core.type.reflect.GenericType<T>)",
6952
6952
"justification": "Refactorings in PR 1666"
6953
+ },
6954
+ {
6955
+ "code": "java.method.returnTypeChangedCovariantly",
6956
+ "old": "method java.lang.Throwable java.lang.Throwable::fillInStackTrace() @ com.fasterxml.jackson.databind.deser.UnresolvedForwardReference",
6957
+ "new": "method com.fasterxml.jackson.databind.deser.UnresolvedForwardReference com.fasterxml.jackson.databind.deser.UnresolvedForwardReference::fillInStackTrace()",
6958
+ "justification": "Upgrade jackson-databind to 2.13.4.1 to address CVEs, API change cause: https://github.com/FasterXML/jackson-databind/issues/3419"
6953
6959
}
6954
6960
]
6955
6961
}
Original file line number Diff line number Diff line change 57
57
<slf4j .version>1.7.26</slf4j .version>
58
58
<reactive-streams .version>1.0.3</reactive-streams .version>
59
59
<json .version>20230227</json .version>
60
- <jackson .version>2.13.2</jackson .version>
61
- <jackson-databind .version>2.13.2.2</jackson-databind .version>
62
- <legacy-jackson .version>1.9.12</legacy-jackson .version>
60
+ <jackson .version>2.13.4</jackson .version>
61
+ <jackson-databind .version>2.13.4.1</jackson-databind .version>
63
62
<!-- optional dependencies -->
64
63
<snappy .version>1.1.10.1</snappy .version>
65
64
<lz4 .version>1.7.1</lz4 .version>
You can’t perform that action at this time.
0 commit comments