You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I've noticed quite a long list of CVEs associated with one of dependencies that 0.10.3 relies on. Do you think it's safe to simply bump version to a non-vulnerable one?
The text was updated successfully, but these errors were encountered:
The library compiles against a historical version for backward compatibility reason - it's perfectly normal and expected to bump Jackson to newer versions
Hi!
I've noticed quite a long list of CVEs associated with one of dependencies that
0.10.3
relies on. Do you think it's safe to simply bump version to a non-vulnerable one?The text was updated successfully, but these errors were encountered: