manuzhang opened a new pull request, #3834:
URL: https://github.com/apache/parquet-java/pull/3834

   ### Rationale for this change
   
   Jackson 2.22.2, which parquet-jackson shades, is affected by CVE-2026-89407 
and CVE-2026-89425 (HIGH) in jackson-core. Both are fixed in 2.22.3. Projects 
that bundle parquet-jackson cannot upgrade the shaded copy themselves; for 
example, Apache Iceberg has to ignore these findings in its Kafka Connect 
runtime CVE scan ([Build: Ignore jackson-core CVEs shaded into 
parquet-jackson](https://github.com/apache/iceberg/pull/18346)). It would help 
to have this in 1.19.0.
   
   ### What changes are included in this PR?
   
   Bump `jackson.version` and `jackson-databind.version` from 2.22.2 to 2.22.3. 
The 2.22.3 jars have the same multi-release versions as 2.22.2 (9, 11, 17, and 
21), which the parquet-jackson shading already relocates.
   
   ### Are these changes tested?
   
   Built parquet-jackson and checked that the shaded jar embeds jackson-core 
and jackson-databind 2.22.3. Existing tests cover the rest.
   
   ### Are there any user-facing changes?
   
   No.
   
   This PR was prepared with Claude Code (Claude Opus 5.5).
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to