Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ODP-2187 Upgrade snakeyaml version to 2.0 #28

Merged
merged 1 commit into from
Sep 4, 2024
Merged

ODP-2187 Upgrade snakeyaml version to 2.0 #28

merged 1 commit into from
Sep 4, 2024

Conversation

senthh
Copy link
Collaborator

@senthh senthh commented Sep 4, 2024

What changes were proposed in this pull request?

Upgrade snakeyaml version to 2.0

We have jackson 2.14. And as per opensource PR [SPARK-43263][BUILD] Upgrade FasterXML jackson to 2.15.0 by bjornjorgensen · Pull Request #40933 · apache/spark , if we have jackson 2.14.2 then we can directly upgrade snakeyaml to 2.0 without any other changes. I m upgrading both jackson and snakeyaml to 2.14.2 and 2.0 respectively.

Why are the changes needed?

Upgrade snakeyaml to 2.0 to fix below CVEs,

CVE-2022-38751
CVE-2022-38752
CVE-2022-41854
CVE-2022-1471

Does this PR introduce any user-facing change?

No

@github-actions github-actions bot added the BUILD label Sep 4, 2024
@senthh senthh merged commit 02b3f43 into ODP-2049 Sep 4, 2024
10 of 13 checks passed
@prabhjyotsingh prabhjyotsingh deleted the ODP-2187 branch September 27, 2024 12:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant