HADOOP-16905. Update jackson-databind to 2.10.3 to relieve us from the endless CVE patches. (#1876)

This commit is contained in:
Wei-Chiu Chuang 2020-03-06 19:18:01 -08:00 committed by GitHub
parent 4062217189
commit 69faaa1d58
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
2 changed files with 9 additions and 2 deletions

View File

@ -339,6 +339,13 @@
<exclude>**/pom.xml</exclude> <exclude>**/pom.xml</exclude>
</excludes> </excludes>
</relocation> </relocation>
<relocation>
<pattern>javax/xml/bind/</pattern>
<shadedPattern>${shaded.dependency.prefix}.javax.xml.bind.</shadedPattern>
<excludes>
<exclude>**/pom.xml</exclude>
</excludes>
</relocation>
<relocation> <relocation>
<pattern>net/</pattern> <pattern>net/</pattern>
<shadedPattern>${shaded.dependency.prefix}.net.</shadedPattern> <shadedPattern>${shaded.dependency.prefix}.net.</shadedPattern>

View File

@ -71,8 +71,8 @@
<!-- jackson versions --> <!-- jackson versions -->
<jackson.version>1.9.13</jackson.version> <jackson.version>1.9.13</jackson.version>
<jackson2.version>2.9.10</jackson2.version> <jackson2.version>2.10.3</jackson2.version>
<jackson2.databind.version>2.9.10.3</jackson2.databind.version> <jackson2.databind.version>2.10.3</jackson2.databind.version>
<!-- httpcomponents versions --> <!-- httpcomponents versions -->
<httpclient.version>4.5.6</httpclient.version> <httpclient.version>4.5.6</httpclient.version>