manuzhang opened a new pull request, #3834: URL: https://github.com/apache/parquet-java/pull/3834
### Rationale for this change Jackson 2.22.2, which parquet-jackson shades, is affected by CVE-2026-89407 and CVE-2026-89425 (HIGH) in jackson-core. Both are fixed in 2.22.3. Projects that bundle parquet-jackson cannot upgrade the shaded copy themselves; for example, Apache Iceberg has to ignore these findings in its Kafka Connect runtime CVE scan ([Build: Ignore jackson-core CVEs shaded into parquet-jackson](https://github.com/apache/iceberg/pull/18346)). It would help to have this in 1.19.0. ### What changes are included in this PR? Bump `jackson.version` and `jackson-databind.version` from 2.22.2 to 2.22.3. The 2.22.3 jars have the same multi-release versions as 2.22.2 (9, 11, 17, and 21), which the parquet-jackson shading already relocates. ### Are these changes tested? Built parquet-jackson and checked that the shaded jar embeds jackson-core and jackson-databind 2.22.3. Existing tests cover the rest. ### Are there any user-facing changes? No. This PR was prepared with Claude Code (Claude Opus 5.5). -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
