Skip to content

Commit 47b1067

Browse files
committed
Upgrade jackson to 2.19 and snakeyaml to 2.14
Code hygene and clearing falsely flagged CVEs
1 parent b8d1af5 commit 47b1067

File tree

2 files changed

+5
-8
lines changed

2 files changed

+5
-8
lines changed

core/build.gradle

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -62,9 +62,8 @@ tasks.japicmp {
6262

6363
configurations.all {
6464
resolutionStrategy {
65-
// use lower Jackson version
66-
force 'com.fasterxml.jackson.core:jackson-databind:2.8.8'
67-
force 'com.fasterxml.jackson.datatype:jackson-datatype-jsr310:2.8.8'
65+
force 'com.fasterxml.jackson.core:jackson-databind:2.19.0'
66+
force 'com.fasterxml.jackson.datatype:jackson-datatype-jsr310:2.19.0'
6867
}
6968
}
7069

@@ -100,7 +99,7 @@ dependencies {
10099
api 'com.github.docker-java:docker-java-transport-zerodep'
101100

102101
shaded 'com.google.guava:guava:33.3.1-jre'
103-
shaded "org.yaml:snakeyaml:1.33"
102+
shaded "org.yaml:snakeyaml:2.4"
104103

105104
shaded 'org.glassfish.main.external:trilead-ssh2-repackaged:4.1.2'
106105

modules/k3s/build.gradle

Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,8 @@ description = "Testcontainers :: K3S"
33
dependencies {
44
api project(":testcontainers")
55

6-
// https://youtu.be/otCpCn0l4Wo
7-
// The core module depends on jackson-databind 2.8.x for backward compatibility.
8-
// Any >2.8 version here is not compatible with jackson-databind 2.8.x.
9-
shaded 'com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.8.8'
6+
// Synchronize with the jackson version, must match major and minor version
7+
shaded 'com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.19.0'
108

119
testImplementation 'io.fabric8:kubernetes-client:6.13.1'
1210
testImplementation 'io.kubernetes:client-java:21.0.1-legacy'

0 commit comments

Comments
 (0)