Script 'mail_helper' called by obssrc
Hello community,
here is the log from the commit of package jackson-databind for
openSUSE:Factory checked in at 2022-10-17 14:58:36
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/jackson-databind (Old)
and /work/SRC/openSUSE:Factory/.jackson-databind.new.2275 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "jackson-databind"
Mon Oct 17 14:58:36 2022 rev:10 rq:1012074 version:2.13.4.2
Changes:
--------
--- /work/SRC/openSUSE:Factory/jackson-databind/jackson-databind.changes
2022-06-19 21:11:04.862145494 +0200
+++
/work/SRC/openSUSE:Factory/.jackson-databind.new.2275/jackson-databind.changes
2022-10-17 14:58:38.182200671 +0200
@@ -1,0 +2,22 @@
+Mon Oct 17 11:36:57 UTC 2022 - Fridrich Strba <[email protected]>
+
+- Update to 2.13.4.2
+ * 2.13.4.2 (13-Oct-2022)
+ + #3627: Gradle module metadata for '2.13.4.1' references
+ non-existent jackson-bom '2.13.4.1' (instead of
+ '2.13.4.20221012')
+ * 2.13.4.1 (12-Oct-2022)
+ + #3590: Add check in primitive value deserializers to avoid
+ deep wrapper array nesting wrt 'UNWRAP_SINGLE_VALUE_ARRAYS'
+ [bsc#1204370, CVE-2022-42003]
+ * 2.13.4 (03-Sep-2022)
+ + #3275: JDK 16 Illegal reflective access for
+ 'Throwable.setCause()' with
+ 'PropertyNamingStrategy.UPPER_CAMEL_CASE'
+ + #3565: 'Arrays.asList()' value deserialization has changed
+ from mutable to immutable in 2.13
+ + #3582: Add check in 'BeanDeserializer._deserializeFromArray()'
+ to prevent use of deeply nested arrays [bsc#1204369,
+ CVE-2022-42004]
+
+-------------------------------------------------------------------
Old:
----
jackson-databind-2.13.3.tar.gz
New:
----
jackson-databind-2.13.4.2.tar.gz
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Other differences:
------------------
++++++ jackson-databind.spec ++++++
--- /var/tmp/diff_new_pack.RLRA33/_old 2022-10-17 14:58:39.142202515 +0200
+++ /var/tmp/diff_new_pack.RLRA33/_new 2022-10-17 14:58:39.146202523 +0200
@@ -17,7 +17,7 @@
Name: jackson-databind
-Version: 2.13.3
+Version: 2.13.4.2
Release: 0
Summary: General data-binding package for Jackson (2.x)
License: Apache-2.0 AND LGPL-2.1-or-later
++++++ jackson-databind-2.13.3.tar.gz -> jackson-databind-2.13.4.2.tar.gz ++++++
/work/SRC/openSUSE:Factory/jackson-databind/jackson-databind-2.13.3.tar.gz
/work/SRC/openSUSE:Factory/.jackson-databind.new.2275/jackson-databind-2.13.4.2.tar.gz
differ: char 19, line 1
++++++ jackson-databind-build.xml ++++++
--- /var/tmp/diff_new_pack.RLRA33/_old 2022-10-17 14:58:39.194202615 +0200
+++ /var/tmp/diff_new_pack.RLRA33/_new 2022-10-17 14:58:39.198202623 +0200
@@ -11,7 +11,7 @@
<property name="project.groupId" value="com.fasterxml.jackson.core"/>
<property name="project.artifactId" value="jackson-databind"/>
<property name="project.name" value="jackson-databind"/>
- <property name="project.version" value="2.13.3"/>
+ <property name="project.version" value="2.13.4.2"/>
<property name="project.vendor" value="FasterXML"/>
<property name="project.description" value="General data-binding
functionality for Jackson: works on core streaming API"/>
<property name="bundle.version" value="${project.version}"/>