Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Aug 29, 2025

Bumps jackson.version from 2.19.2 to 2.20.
Updates com.fasterxml.jackson.core:jackson-databind from 2.19.2 to 2.20

Updates com.fasterxml.jackson.core:jackson-core from 2.19.2 to 2.20

Updates com.fasterxml.jackson.core:jackson-annotations from 2.19.2 to 2.20

Commits

Updates com.fasterxml.jackson.datatype:jackson-datatype-jsr310 from 2.19.2 to 2.20

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Pull requests that update a dependency file maven labels Aug 29, 2025
@phipag
Copy link
Contributor

phipag commented Sep 2, 2025

CI errors with

 Error:  Failed to execute goal on project powertools-serialization: Could not resolve dependencies for project software.amazon.lambda:powertools-serialization:jar:2.3.0
Error:  dependency: com.fasterxml.jackson.core:jackson-databind:jar:2.20 (compile)
Error:  	Could not find artifact com.fasterxml.jackson.core:jackson-databind:jar:2.20 in central (https://repo.maven.apache.org/maven2)
Error:  -> [Help 1]

The correct version name is 2.20**.0** with a zero at the end.
https://mvnrepository.com/artifact/com.fasterxml.jackson.core/jackson-databind/2.20.0

@phipag
Copy link
Contributor

phipag commented Sep 2, 2025

@dependabot recreate

Bumps `jackson.version` from 2.19.2 to 2.20.

Updates `com.fasterxml.jackson.core:jackson-databind` from 2.19.2 to 2.20

Updates `com.fasterxml.jackson.core:jackson-core` from 2.19.2 to 2.20

Updates `com.fasterxml.jackson.core:jackson-annotations` from 2.19.2 to 2.20
- [Commits](https://github.com/FasterXML/jackson/commits)

Updates `com.fasterxml.jackson.datatype:jackson-datatype-jsr310` from 2.19.2 to 2.20

---
updated-dependencies:
- dependency-name: com.fasterxml.jackson.core:jackson-databind
  dependency-version: '2.20'
  dependency-type: direct:development
  update-type: version-update:semver-minor
- dependency-name: com.fasterxml.jackson.core:jackson-core
  dependency-version: '2.20'
  dependency-type: direct:production
  update-type: version-update:semver-minor
- dependency-name: com.fasterxml.jackson.core:jackson-annotations
  dependency-version: '2.20'
  dependency-type: direct:production
  update-type: version-update:semver-minor
- dependency-name: com.fasterxml.jackson.datatype:jackson-datatype-jsr310
  dependency-version: '2.20'
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot force-pushed the dependabot/maven/jackson.version-2.20 branch from dcefaa9 to 2105f8e Compare September 2, 2025 13:07
@phipag
Copy link
Contributor

phipag commented Sep 3, 2025

There is an incosistency in how Jackson names release version. Jackson annotations uses 2.20 while all other use 2.20.0. This means it is not possible anymore to update a single Maven property which is what Dependabot tried to do here. Related issue: FasterXML/jackson-annotations#307

In the related issue, it is recommended to migrate to the Jackson BOM: https://github.com/FasterXML/jackson-bom

Let me do this here since it is a more stable approach in updating jackson version so that they are compatible with each other.

Comment in Jackson BOM:

    <!-- 25-Sep-2019, tatu: With Jackson 2.x we release full patch-level versions
           of annotations BUT they are all identical, content-wise.
           Given this, annotations could EITHER be `2.11.0` OR `${jackson.version}`.
           Based on dev feedback, with 2.10 we will do latter. It apparently is less
           confusing than alternative.
    -->
    <!-- 10-Jul-2025, tatu: Jackson 2.20 finally drops patch from `jackson-annotations`:
        hence we need to separate it out.
      -->
    <jackson.version.annotations>2.20</jackson.version.annotations>

@pull-request-size pull-request-size bot added size/S and removed size/XS labels Sep 3, 2025
@sonarqubecloud
Copy link

sonarqubecloud bot commented Sep 3, 2025

@phipag phipag merged commit de9ba8b into main Sep 3, 2025
15 checks passed
@phipag phipag deleted the dependabot/maven/jackson.version-2.20 branch September 3, 2025 17:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file maven size/S

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants