Skip to content

Commit

Permalink
Add snakeyaml 1.32 dependency until jackson is updated
Browse files Browse the repository at this point in the history
The Jackson dataformat library depends on snakeyaml 1.31.  The snakeyaml
1.31 library has a vulnerability that is resolved in snakeyaml 1.32.
Include snakeyaml 1.32 as an explicit dependency until Jackson dataformat
is updated to use a newer snakeyaml library.
  • Loading branch information
MarkEWaite committed Sep 23, 2022
1 parent 04cfb26 commit 6239603
Showing 1 changed file with 6 additions and 11 deletions.
17 changes: 6 additions & 11 deletions plugin-management-library/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -13,17 +13,6 @@
<version>${revision}${changelist}</version>
<packaging>jar</packaging>

<dependencyManagement>
<dependencies>
<!-- TODO: Remove when jackson dataformat snakeyaml dependency is at least 1.32 -->
<dependency>
<groupId>org.yaml</groupId>
<artifactId>snakeyaml</artifactId>
<version>1.32</version>
</dependency>
</dependencies>
</dependencyManagement>

<dependencies>
<dependency>
<groupId>org.jenkins-ci</groupId>
Expand Down Expand Up @@ -76,6 +65,12 @@
<artifactId>jackson-dataformat-yaml</artifactId>
<version>2.13.4</version>
</dependency>
<!-- TODO: Remove when jackson dataformat snakeyaml dependency is at least 1.32 -->
<dependency>
<groupId>org.yaml</groupId>
<artifactId>snakeyaml</artifactId>
<version>1.32</version>
</dependency>
<dependency>
<groupId>com.github.spotbugs</groupId>
<artifactId>spotbugs-annotations</artifactId>
Expand Down

0 comments on commit 6239603

Please sign in to comment.