lhotari opened a new issue, #26126:
URL: https://github.com/apache/pulsar/issues/26126

   > `2.21.4` resolves six of the seven advisories, but `CVE-2026-54515` is 
only fixed in `2.21.5`, which was never published to Maven Central (the 2.21.x 
line went straight from 2.21.4 to 2.22.0). `2.22.0` is therefore the lowest 
available version that clears all seven.
   
   I think that we should downgrade back to 2.21.x [since it's a LTS 
branch](https://github.com/FasterXML/jackson/wiki/Jackson-Releases#open-branches).
 The 2.21.5 release is planned, but it hasn't been released yet: 
https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.21
   
   _Originally posted by @lhotari in 
https://github.com/apache/pulsar/issues/26101#issuecomment-4852680356_
               


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to