Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump org.json:json from 20230227 to 20231013 #221

Merged
merged 1 commit into from
Nov 7, 2023

Conversation

rsahoo7495
Copy link
Contributor

@rsahoo7495 rsahoo7495 commented Nov 6, 2023

As we need to Bump json-20230227 to 20231013 to fix vulnerabilities. which is a transitive dependency from jackson-datatype-json-org, which is coming from jackson-bom.
As jackson-bom 2.16.0-rc1 is a release candidate and under development, so updating org.json directly in pom to 20231013.

Testing done

mvn verify -> success

Submitter checklist

@rsahoo7495 rsahoo7495 marked this pull request as ready for review November 6, 2023 07:25
@rsahoo7495 rsahoo7495 requested a review from a team as a code owner November 6, 2023 07:25
Copy link
Member

@jtnord jtnord left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this is a release candidate and under development, it is not something that should go into a production environment, please investigate another way of obtaining the newer depependency

@rsahoo7495 rsahoo7495 changed the title Bump jackson-bom from 2.15.3 to 2.16.0-rc1 Bump org.json:json from 20230227 to 20231013 Nov 7, 2023
@rsahoo7495
Copy link
Contributor Author

this is a release candidate and under development, it is not something that should go into a production environment, please investigate another way of obtaining the newer depependency

update org.json directly in pom.xml to 20231013

@jtnord jtnord added the chore label Nov 7, 2023
@jtnord jtnord merged commit 341d615 into jenkinsci:master Nov 7, 2023
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants