[ 
https://issues.apache.org/jira/browse/TINKERPOP-2401?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17190456#comment-17190456
 ] 

ASF GitHub Bot commented on TINKERPOP-2401:
-------------------------------------------

spmallette opened a new pull request #1324:
URL: https://github.com/apache/tinkerpop/pull/1324


   https://issues.apache.org/jira/browse/TINKERPOP-2401
   
   On merge, there may need to be some polish up of CHANGELOG and JIRAs so that 
things dont look confusing as to when they occurred. Other than that, I 
couldn't find any real breaking changes here so decided to bring 3.4-dev all 
the way up to 2.11.x.
   
   All tests pass with `docker/build.sh -t -n -i`
   
   VOTE +1


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
[email protected]


> Upgrade Jackson-databind to 2.11.x
> ----------------------------------
>
>                 Key: TINKERPOP-2401
>                 URL: https://issues.apache.org/jira/browse/TINKERPOP-2401
>             Project: TinkerPop
>          Issue Type: Improvement
>          Components: build-release
>    Affects Versions: 3.4.8
>            Reporter: Divij Vaidya
>            Assignee: Stephen Mallette
>            Priority: Major
>
> Currently TinkerPop uses 2.9.10.5 version which has known [security 
> vulnerabilities|https://www.cvedetails.com/vulnerability-list/vendor_id-15866/product_id-42991/version_id-353769/Fasterxml-Jackson-databind-2.9.10.html].
> As per guidance from Jackson-databind, 2.9.x is a non-active branch. To quote 
> from https://github.com/FasterXML/jackson
> {quote}2.9: non-active branch from which micro-patch releases (like 2.9.10.5) 
> MAY be made for individual components (jackson-databind usually){quote}
> Backport 2.11.x from master to 3.4-dev



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Reply via email to