srowen commented on issue #24418: [SPARK-24601][SPARK-27051][BACKPORT][CORE] 
Update to Jackson 2.9.8
URL: https://github.com/apache/spark/pull/24418#issuecomment-485269004
 
 
   I support this, and wanted to more fully explain the logic, as it occurs to 
me not all of it was visible in the conversation here:
   
   - The Jackson security issue has come up a few times on JIRAs
   - It was actually raised again on the security@ list for the project last 
week
   - I can also say this has been raised by a few customers at Databricks, FWIW
   - Having the older version is also beginning to cause problems with apps 
that want to include third-party libs that depend on newer Jackson
   - There's a perf boost
   
   Weighing that against the relatively small behavior change I think it's the 
right thing for 2.4.x.
   
   This won't go into 2.4.2 unless there is another RC. If not, it'll be in 
2.4.3.

----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
 
For queries about this service, please contact Infrastructure at:
[email protected]


With regards,
Apache Git Services

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to