Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[close #567] upgrade jackson-databind to 2.13.2.2 to fix CVE-2020-36518 (#584) #585

Merged
merged 2 commits into from
Apr 7, 2022

Conversation

ti-srebot
Copy link
Collaborator

@ti-srebot ti-srebot commented Apr 7, 2022

cherry-pick #584 to release-3.1
You can switch your code base to this Pull Request by using git-extras:

# In client-java repo:
git pr https://github.com/tikv/client-java/pull/585

After apply modifications, you can push your change to this PR via:

git push [email protected]:ti-srebot/client-java.git pr/585:release-3.1-7fa24c3206d1

Signed-off-by: iosmanthus [email protected]

What problem does this PR solve?

Issue Number: close #567

Problem Description:

upgrade jackson-databind to 2.13.2.2 to fix CVE-2020-36518

What is changed and how does it work?

Related changes

  • Need to cherry-pick the release branch
  • Need to update the documentation
  • Need to be included in the release note
  • NO related changes

@ti-srebot
Copy link
Collaborator Author

/run-all-tests

@codecov
Copy link

codecov bot commented Apr 7, 2022

Codecov Report

❗ No coverage uploaded for pull request base (release-3.1@1dc906b). Click here to learn what that means.
The diff coverage is n/a.

@@              Coverage Diff               @@
##             release-3.1     #585   +/-   ##
==============================================
  Coverage               ?   30.04%           
  Complexity             ?     1162           
==============================================
  Files                  ?      263           
  Lines                  ?    16639           
  Branches               ?     1897           
==============================================
  Hits                   ?     5000           
  Misses                 ?    11081           
  Partials               ?      558           

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 1dc906b...f7b2c9c. Read the comment docs.

@iosmanthus
Copy link
Member

/LGTM

@zz-jason zz-jason merged commit d0a3218 into tikv:release-3.1 Apr 7, 2022
iosmanthus added a commit that referenced this pull request Apr 8, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants