From 69e0499cf07dac1d993d97f43e588ddc324339f7 Mon Sep 17 00:00:00 2001 From: Lari Hotari Date: Mon, 10 Jan 2022 22:09:13 +0200 Subject: [PATCH] [Security] Upgrade Jackson to 2.12.6 (#13694) * [Security] Upgrade Jackson to 2.12.6 * update LICENSE files (cherry picked from commit f8a9159efd14298e7afff82068aeb50eef95e25e) --- .../server/src/assemble/LICENSE.bin.txt | 16 +++++------ pom.xml | 4 +-- pulsar-sql/presto-distribution/LICENSE | 28 +++++++++---------- pulsar-sql/presto-distribution/pom.xml | 4 +-- 4 files changed, 26 insertions(+), 26 deletions(-) diff --git a/distribution/server/src/assemble/LICENSE.bin.txt b/distribution/server/src/assemble/LICENSE.bin.txt index 1620c9f61754f..b2c1da45aeadd 100644 --- a/distribution/server/src/assemble/LICENSE.bin.txt +++ b/distribution/server/src/assemble/LICENSE.bin.txt @@ -312,14 +312,14 @@ The Apache Software License, Version 2.0 * JCommander -- com.beust-jcommander-1.78.jar * High Performance Primitive Collections for Java -- com.carrotsearch-hppc-0.7.3.jar * Jackson - - com.fasterxml.jackson.core-jackson-annotations-2.12.3.jar - - com.fasterxml.jackson.core-jackson-core-2.12.3.jar - - com.fasterxml.jackson.core-jackson-databind-2.12.3.jar - - com.fasterxml.jackson.dataformat-jackson-dataformat-yaml-2.12.3.jar - - com.fasterxml.jackson.jaxrs-jackson-jaxrs-base-2.12.3.jar - - com.fasterxml.jackson.jaxrs-jackson-jaxrs-json-provider-2.12.3.jar - - com.fasterxml.jackson.module-jackson-module-jaxb-annotations-2.12.3.jar - - com.fasterxml.jackson.module-jackson-module-jsonSchema-2.12.3.jar + - com.fasterxml.jackson.core-jackson-annotations-2.12.6.jar + - com.fasterxml.jackson.core-jackson-core-2.12.6.jar + - com.fasterxml.jackson.core-jackson-databind-2.12.6.jar + - com.fasterxml.jackson.dataformat-jackson-dataformat-yaml-2.12.6.jar + - com.fasterxml.jackson.jaxrs-jackson-jaxrs-base-2.12.6.jar + - com.fasterxml.jackson.jaxrs-jackson-jaxrs-json-provider-2.12.6.jar + - com.fasterxml.jackson.module-jackson-module-jaxb-annotations-2.12.6.jar + - com.fasterxml.jackson.module-jackson-module-jsonSchema-2.12.6.jar * Caffeine -- com.github.ben-manes.caffeine-caffeine-2.9.1.jar * Conscrypt -- org.conscrypt-conscrypt-openjdk-uber-2.5.2.jar * Proto Google Common Protos -- com.google.api.grpc-proto-google-common-protos-1.17.0.jar diff --git a/pom.xml b/pom.xml index 88d2e5813e532..ed0138d064399 100644 --- a/pom.xml +++ b/pom.xml @@ -122,8 +122,8 @@ flexible messaging model and an intuitive client API. 2.17.1 1.69 1.0.2 - 2.12.3 - 2.12.3 + 2.12.6 + 2.12.6 0.9.11 1.6.2 8.37 diff --git a/pulsar-sql/presto-distribution/LICENSE b/pulsar-sql/presto-distribution/LICENSE index a988218649c3a..69c387bb5c53b 100644 --- a/pulsar-sql/presto-distribution/LICENSE +++ b/pulsar-sql/presto-distribution/LICENSE @@ -207,19 +207,19 @@ This projects includes binary packages with the following licenses: The Apache Software License, Version 2.0 * Jackson - - jackson-annotations-2.12.3.jar - - jackson-core-2.12.3.jar - - jackson-databind-2.12.3.jar - - jackson-dataformat-smile-2.12.3.jar - - jackson-datatype-guava-2.12.3.jar - - jackson-datatype-jdk8-2.12.3.jar - - jackson-datatype-joda-2.12.3.jar - - jackson-datatype-jsr310-2.12.3.jar - - jackson-dataformat-yaml-2.12.3.jar - - jackson-jaxrs-base-2.12.3.jar - - jackson-jaxrs-json-provider-2.12.3.jar - - jackson-module-jaxb-annotations-2.12.3.jar - - jackson-module-jsonSchema-2.12.3.jar + - jackson-annotations-2.12.6.jar + - jackson-core-2.12.6.jar + - jackson-databind-2.12.6.jar + - jackson-dataformat-smile-2.12.6.jar + - jackson-datatype-guava-2.12.6.jar + - jackson-datatype-jdk8-2.12.6.jar + - jackson-datatype-joda-2.12.6.jar + - jackson-datatype-jsr310-2.12.6.jar + - jackson-dataformat-yaml-2.12.6.jar + - jackson-jaxrs-base-2.12.6.jar + - jackson-jaxrs-json-provider-2.12.6.jar + - jackson-module-jaxb-annotations-2.12.6.jar + - jackson-module-jsonSchema-2.12.6.jar * Guava - guava-30.1-jre.jar - listenablefuture-9999.0-empty-to-avoid-conflict-with-guava.jar @@ -440,7 +440,7 @@ The Apache Software License, Version 2.0 * Snappy - snappy-java-1.1.7.jar * Jackson - - jackson-module-parameter-names-2.12.3.jar + - jackson-module-parameter-names-2.12.6.jar * Java Assist - javassist-3.25.0-GA.jar * Java Native Access diff --git a/pulsar-sql/presto-distribution/pom.xml b/pulsar-sql/presto-distribution/pom.xml index 39096520c6c4d..24cefa1c54a5b 100644 --- a/pulsar-sql/presto-distribution/pom.xml +++ b/pulsar-sql/presto-distribution/pom.xml @@ -39,10 +39,10 @@ 2.6 0.0.12 4.2.0 - 2.12.3 + 2.12.6 - 2.12.3 + 2.12.6 3.0.5 30.1-jre 2.12.1