Skip to content
Discussion options

You must be logged in to vote

We only do immediate releases if we're susceptible to the actual problem (which is almost never the case). Downstream consumers shouldn't be using our transitive dependencies as the sole source of versioning if they use the dependencies directly. Those projects are expected to declare the dependency and bump it to a newer version themselves if they use it directly.

The same is true of CVEs in the libraries used for converters or adapters.

The next release will probably be in a month or two when the new Jackson 3 converter is finally merged.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@deliseev-r7
Comment options

Answer selected by deliseev-r7
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants