Skip to content

Commit

Permalink
[Security] Upgrade Jackson to 2.12.6 (#13694)
Browse files Browse the repository at this point in the history
* [Security] Upgrade Jackson to 2.12.6

* update LICENSE files

(cherry picked from commit f8a9159)
  • Loading branch information
lhotari authored and codelipenghui committed Jan 18, 2022
1 parent ebec861 commit 69e0499
Show file tree
Hide file tree
Showing 4 changed files with 26 additions and 26 deletions.
16 changes: 8 additions & 8 deletions distribution/server/src/assemble/LICENSE.bin.txt
Expand Up @@ -312,14 +312,14 @@ The Apache Software License, Version 2.0
* JCommander -- com.beust-jcommander-1.78.jar
* High Performance Primitive Collections for Java -- com.carrotsearch-hppc-0.7.3.jar
* Jackson
- com.fasterxml.jackson.core-jackson-annotations-2.12.3.jar
- com.fasterxml.jackson.core-jackson-core-2.12.3.jar
- com.fasterxml.jackson.core-jackson-databind-2.12.3.jar
- com.fasterxml.jackson.dataformat-jackson-dataformat-yaml-2.12.3.jar
- com.fasterxml.jackson.jaxrs-jackson-jaxrs-base-2.12.3.jar
- com.fasterxml.jackson.jaxrs-jackson-jaxrs-json-provider-2.12.3.jar
- com.fasterxml.jackson.module-jackson-module-jaxb-annotations-2.12.3.jar
- com.fasterxml.jackson.module-jackson-module-jsonSchema-2.12.3.jar
- com.fasterxml.jackson.core-jackson-annotations-2.12.6.jar
- com.fasterxml.jackson.core-jackson-core-2.12.6.jar
- com.fasterxml.jackson.core-jackson-databind-2.12.6.jar
- com.fasterxml.jackson.dataformat-jackson-dataformat-yaml-2.12.6.jar
- com.fasterxml.jackson.jaxrs-jackson-jaxrs-base-2.12.6.jar
- com.fasterxml.jackson.jaxrs-jackson-jaxrs-json-provider-2.12.6.jar
- com.fasterxml.jackson.module-jackson-module-jaxb-annotations-2.12.6.jar
- com.fasterxml.jackson.module-jackson-module-jsonSchema-2.12.6.jar
* Caffeine -- com.github.ben-manes.caffeine-caffeine-2.9.1.jar
* Conscrypt -- org.conscrypt-conscrypt-openjdk-uber-2.5.2.jar
* Proto Google Common Protos -- com.google.api.grpc-proto-google-common-protos-1.17.0.jar
Expand Down
4 changes: 2 additions & 2 deletions pom.xml
Expand Up @@ -122,8 +122,8 @@ flexible messaging model and an intuitive client API.</description>
<log4j2.version>2.17.1</log4j2.version>
<bouncycastle.version>1.69</bouncycastle.version>
<bouncycastlefips.version>1.0.2</bouncycastlefips.version>
<jackson.version>2.12.3</jackson.version>
<jackson.databind.version>2.12.3</jackson.databind.version>
<jackson.version>2.12.6</jackson.version>
<jackson.databind.version>2.12.6</jackson.databind.version>
<reflections.version>0.9.11</reflections.version>
<swagger.version>1.6.2</swagger.version>
<puppycrawl.checkstyle.version>8.37</puppycrawl.checkstyle.version>
Expand Down
28 changes: 14 additions & 14 deletions pulsar-sql/presto-distribution/LICENSE
Expand Up @@ -207,19 +207,19 @@ This projects includes binary packages with the following licenses:
The Apache Software License, Version 2.0

* Jackson
- jackson-annotations-2.12.3.jar
- jackson-core-2.12.3.jar
- jackson-databind-2.12.3.jar
- jackson-dataformat-smile-2.12.3.jar
- jackson-datatype-guava-2.12.3.jar
- jackson-datatype-jdk8-2.12.3.jar
- jackson-datatype-joda-2.12.3.jar
- jackson-datatype-jsr310-2.12.3.jar
- jackson-dataformat-yaml-2.12.3.jar
- jackson-jaxrs-base-2.12.3.jar
- jackson-jaxrs-json-provider-2.12.3.jar
- jackson-module-jaxb-annotations-2.12.3.jar
- jackson-module-jsonSchema-2.12.3.jar
- jackson-annotations-2.12.6.jar
- jackson-core-2.12.6.jar
- jackson-databind-2.12.6.jar
- jackson-dataformat-smile-2.12.6.jar
- jackson-datatype-guava-2.12.6.jar
- jackson-datatype-jdk8-2.12.6.jar
- jackson-datatype-joda-2.12.6.jar
- jackson-datatype-jsr310-2.12.6.jar
- jackson-dataformat-yaml-2.12.6.jar
- jackson-jaxrs-base-2.12.6.jar
- jackson-jaxrs-json-provider-2.12.6.jar
- jackson-module-jaxb-annotations-2.12.6.jar
- jackson-module-jsonSchema-2.12.6.jar
* Guava
- guava-30.1-jre.jar
- listenablefuture-9999.0-empty-to-avoid-conflict-with-guava.jar
Expand Down Expand Up @@ -440,7 +440,7 @@ The Apache Software License, Version 2.0
* Snappy
- snappy-java-1.1.7.jar
* Jackson
- jackson-module-parameter-names-2.12.3.jar
- jackson-module-parameter-names-2.12.6.jar
* Java Assist
- javassist-3.25.0-GA.jar
* Java Native Access
Expand Down
4 changes: 2 additions & 2 deletions pulsar-sql/presto-distribution/pom.xml
Expand Up @@ -39,10 +39,10 @@
<objenesis.version>2.6</objenesis.version>
<objectsize.version>0.0.12</objectsize.version>
<guice.version>4.2.0</guice.version>
<jackson.version>2.12.3</jackson.version>
<jackson.version>2.12.6</jackson.version>
<!--fix Security Vulnerabilities-->
<!--https://www.cvedetails.com/vulnerability-list/vendor_id-15866/product_id-42991/Fasterxml-Jackson-databind.html-->
<jackson.databind.version>2.12.3</jackson.databind.version>
<jackson.databind.version>2.12.6</jackson.databind.version>
<maven.version>3.0.5</maven.version>
<guava.version>30.1-jre</guava.version>
<asynchttpclient.version>2.12.1</asynchttpclient.version>
Expand Down

0 comments on commit 69e0499

Please sign in to comment.