[ https://issues.apache.org/jira/browse/HBASE-22728?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16894547#comment-16894547 ]
Andrew Purtell commented on HBASE-22728: ---------------------------------------- It’s more a concern about if downstreamers have taken a dependency. We try to be careful about indirectly breaking things. See relevant sections of our compatibility guidelines. Sure, please feel free to post a patch. That would move this forward in a useful way I’m sure. > Upgrade jackson dependencies in branch-1 > ---------------------------------------- > > Key: HBASE-22728 > URL: https://issues.apache.org/jira/browse/HBASE-22728 > Project: HBase > Issue Type: Sub-task > Affects Versions: 1.4.10, 1.3.5 > Reporter: Andrew Purtell > Priority: Major > Fix For: 1.5.0, 1.3.6, 1.4.11 > > > Avoid Jackson versions and dependencies with known CVEs -- This message was sent by Atlassian JIRA (v7.6.14#76016)