From 35c447d754df18ed0b20171171e7842f6e970b22 Mon Sep 17 00:00:00 2001 From: gengjiaan Date: Tue, 24 Sep 2019 15:36:36 +0800 Subject: [PATCH 1/2] Upgrade jackson-databind to 2.9.10 and fix vulnerabilities. --- pom.xml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pom.xml b/pom.xml index 2396c5168b166..2ea699371b44f 100644 --- a/pom.xml +++ b/pom.xml @@ -170,8 +170,8 @@ true 1.9.13 - 2.9.9 - 2.9.9.3 + 2.9.10 + 2.9.10 1.1.7.3 1.1.2 1.10 From 9cbd46fc8ac3e1eb83e1ec20e9b6f6110b2caa71 Mon Sep 17 00:00:00 2001 From: gengjiaan Date: Wed, 25 Sep 2019 10:20:25 +0800 Subject: [PATCH 2/2] update the manifest. --- dev/deps/spark-deps-hadoop-2.7 | 14 +++++++------- dev/deps/spark-deps-hadoop-3.2 | 14 +++++++------- 2 files changed, 14 insertions(+), 14 deletions(-) diff --git a/dev/deps/spark-deps-hadoop-2.7 b/dev/deps/spark-deps-hadoop-2.7 index 2da4c9e44b29e..21d78b405b313 100644 --- a/dev/deps/spark-deps-hadoop-2.7 +++ b/dev/deps/spark-deps-hadoop-2.7 @@ -88,16 +88,16 @@ httpclient-4.5.6.jar httpcore-4.4.10.jar istack-commons-runtime-3.0.8.jar ivy-2.4.0.jar -jackson-annotations-2.9.9.jar -jackson-core-2.9.9.jar +jackson-annotations-2.9.10.jar +jackson-core-2.9.10.jar jackson-core-asl-1.9.13.jar -jackson-databind-2.9.9.3.jar -jackson-dataformat-yaml-2.9.9.jar +jackson-databind-2.9.10.jar +jackson-dataformat-yaml-2.9.10.jar jackson-jaxrs-1.9.13.jar jackson-mapper-asl-1.9.13.jar -jackson-module-jaxb-annotations-2.9.9.jar -jackson-module-paranamer-2.9.9.jar -jackson-module-scala_2.12-2.9.9.jar +jackson-module-jaxb-annotations-2.9.10.jar +jackson-module-paranamer-2.9.10.jar +jackson-module-scala_2.12-2.9.10.jar jackson-xc-1.9.13.jar jakarta.annotation-api-1.3.4.jar jakarta.inject-2.5.0.jar diff --git a/dev/deps/spark-deps-hadoop-3.2 b/dev/deps/spark-deps-hadoop-3.2 index 2226baeadfba1..7fa10f704c2dc 100644 --- a/dev/deps/spark-deps-hadoop-3.2 +++ b/dev/deps/spark-deps-hadoop-3.2 @@ -89,17 +89,17 @@ httpclient-4.5.6.jar httpcore-4.4.10.jar istack-commons-runtime-3.0.8.jar ivy-2.4.0.jar -jackson-annotations-2.9.9.jar -jackson-core-2.9.9.jar +jackson-annotations-2.9.10.jar +jackson-core-2.9.10.jar jackson-core-asl-1.9.13.jar -jackson-databind-2.9.9.3.jar -jackson-dataformat-yaml-2.9.9.jar +jackson-databind-2.9.10.jar +jackson-dataformat-yaml-2.9.10.jar jackson-jaxrs-base-2.9.5.jar jackson-jaxrs-json-provider-2.9.5.jar jackson-mapper-asl-1.9.13.jar -jackson-module-jaxb-annotations-2.9.9.jar -jackson-module-paranamer-2.9.9.jar -jackson-module-scala_2.12-2.9.9.jar +jackson-module-jaxb-annotations-2.9.10.jar +jackson-module-paranamer-2.9.10.jar +jackson-module-scala_2.12-2.9.10.jar jakarta.annotation-api-1.3.4.jar jakarta.inject-2.5.0.jar jakarta.ws.rs-api-2.1.5.jar