Skip to content

GH-3410: Bump jackson dependencies from 2.19.2 to 2.21.2#3460

Merged
wgtmac merged 1 commit intoapache:masterfrom
manuzhang:upgrade-jackson
Apr 2, 2026
Merged

GH-3410: Bump jackson dependencies from 2.19.2 to 2.21.2#3460
wgtmac merged 1 commit intoapache:masterfrom
manuzhang:upgrade-jackson

Conversation

@manuzhang
Copy link
Copy Markdown
Member

@manuzhang manuzhang commented Apr 2, 2026

Rationale for this change

Closes #3410, fixing GHSA-72hv-8253-57qq
This should supersede #3456 and #3439

What changes are included in this PR?

  • Upgrade jackson-core from 2.19.2 to 2.21.2
  • Upgrade jackson-databind from 2.19.2 to 2.21.2
  • Add jackson-annotations 2.21 as a separate dependency

Are these changes tested?

Existing tests.

Are there any user-facing changes?

No.

@wgtmac
Copy link
Copy Markdown
Member

wgtmac commented Apr 2, 2026

Thank you, @manuzhang!

@wgtmac wgtmac merged commit d9612c4 into apache:master Apr 2, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

parquet-jackson being flagged as vulnerable

2 participants