Skip to content

fix: bump transitive jackson deps and spring to resolve CVEs - #99

Merged
meotch merged 1 commit into
masterfrom
mitch/bump_spring_and_jackson_to_resolve_cves
Oct 5, 2026
Merged

meotch merged 1 commit into
masterfrom
mitch/bump_spring_and_jackson_to_resolve_cves

Conversation

@meotch

@meotch meotch commented Oct 5, 2026 •

Copy link
Copy Markdown

Summary of Changes

Bumps com.fasterxml.jackson.core:jackson-core, Spring to 4.1.+ and io.nats:jnats to 2.26.3 to resolve some CVEs causing us to break allowed CVE thresholds in connector pipelines. Also fixes some formatting

Fixes MC-16512

Public API Additions/Changes

None

Downstream Consumer Impact

None

How Has This Been Tested?

Tested locally against path-connector-central-pacific

Checklist:

  • My code follows the style guidelines of this project
  • I have performed a self-review of my code
  • I have made corresponding changes to the documentation
  • My changes generate no new warnings
  • I have added tests that prove my fix is effective or that my feature works

@meotch
meotch merged commit db29445 into master Oct 5, 2026
7 checks passed
@meotch
meotch deleted the mitch/bump_spring_and_jackson_to_resolve_cves branch October 5, 2026 18:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants