Skip to content

Commit 61a2b27

Browse files
author
Carter Kozak
authored
Upgrade jackson-databind to 2.13.2.1 (CVE-2020-36518) (#682)
1 parent b3ed8bd commit 61a2b27

File tree

3 files changed

+30
-28
lines changed

3 files changed

+30
-28
lines changed

build.gradle

Lines changed: 9 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,11 @@
11
buildscript {
22
repositories {
3-
gradlePluginPortal()
4-
mavenCentral()
3+
gradlePluginPortal() {
4+
metadataSources { mavenPom(); ignoreGradleMetadataRedirection() }
5+
}
6+
mavenCentral() {
7+
metadataSources { mavenPom(); ignoreGradleMetadataRedirection() }
8+
}
59
}
610

711
dependencies {
@@ -33,7 +37,9 @@ allprojects {
3337
version = rootProject.version
3438

3539
repositories {
36-
mavenCentral()
40+
mavenCentral() {
41+
metadataSources { mavenPom(); ignoreGradleMetadataRedirection() }
42+
}
3743
}
3844
}
3945

versions.lock

Lines changed: 20 additions & 25 deletions
Original file line numberDiff line numberDiff line change
@@ -5,13 +5,12 @@ com.diffplug.durian:durian-io:1.2.0 (1 constraints: 1313c62d)
55
com.diffplug.spotless:spotless-lib:2.23.0 (2 constraints: ea24bde5)
66
com.diffplug.spotless:spotless-lib-extra:2.23.0 (1 constraints: 47131a41)
77
com.diffplug.spotless:spotless-plugin-gradle:6.3.0 (1 constraints: 0b051236)
8-
com.fasterxml.jackson:jackson-bom:2.13.2 (6 constraints: fe7c7c05)
9-
com.fasterxml.jackson.core:jackson-annotations:2.13.2 (3 constraints: 7826a4c4)
10-
com.fasterxml.jackson.core:jackson-core:2.13.2 (6 constraints: f76b550e)
11-
com.fasterxml.jackson.core:jackson-databind:2.13.2 (5 constraints: 705903c1)
12-
com.fasterxml.jackson.datatype:jackson-datatype-guava:2.13.2 (2 constraints: f1138182)
13-
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:2.13.2 (2 constraints: f1138182)
14-
com.fasterxml.jackson.module:jackson-module-parameter-names:2.13.2 (2 constraints: f1138182)
8+
com.fasterxml.jackson.core:jackson-annotations:2.13.2 (2 constraints: c1174d71)
9+
com.fasterxml.jackson.core:jackson-core:2.13.2 (5 constraints: 405d9c93)
10+
com.fasterxml.jackson.core:jackson-databind:2.13.2.1 (4 constraints: 184b68a5)
11+
com.fasterxml.jackson.datatype:jackson-datatype-guava:2.13.2 (1 constraints: 3a053a3b)
12+
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:2.13.2 (1 constraints: 3a053a3b)
13+
com.fasterxml.jackson.module:jackson-module-parameter-names:2.13.2 (1 constraints: 3a053a3b)
1514
com.google.auto:auto-common:1.2 (2 constraints: fb206329)
1615
com.google.auto.service:auto-service:1.0.1 (1 constraints: 0405f135)
1716
com.google.auto.service:auto-service-annotations:1.0.1 (1 constraints: 9b0f6786)
@@ -33,7 +32,7 @@ org.immutables:value:2.8.8 (1 constraints: 14051536)
3332
org.slf4j:slf4j-api:1.7.36 (2 constraints: bd13787c)
3433

3534
[Test dependencies]
36-
cglib:cglib-nodep:3.3.0 (2 constraints: 7a1acf3c)
35+
cglib:cglib-nodep:3.2.2 (1 constraints: 490ded24)
3736
com.google.auto.value:auto-value:1.5.3 (1 constraints: 1c121afb)
3837
com.google.auto.value:auto-value-annotations:1.8.1 (1 constraints: 620a29b9)
3938
com.google.guava:guava-testlib:27.0.1-jre (1 constraints: aa067c53)
@@ -42,24 +41,20 @@ com.google.truth:truth:1.1.3 (3 constraints: b72b7cb8)
4241
com.google.truth.extensions:truth-java8-extension:0.37 (1 constraints: ef11ffe8)
4342
com.netflix.nebula:nebula-test:10.0.0 (1 constraints: 3305273b)
4443
junit:junit:4.13.2 (7 constraints: 796291b5)
45-
net.bytebuddy:byte-buddy:1.10.16 (1 constraints: 950dfa39)
46-
org.assertj:assertj-core:3.22.0 (2 constraints: 65174647)
44+
org.apiguardian:apiguardian-api:1.1.2 (7 constraints: 9d791b5f)
45+
org.assertj:assertj-core:3.22.0 (1 constraints: 39053f3b)
4746
org.hamcrest:hamcrest:2.2 (1 constraints: d20cdc04)
4847
org.hamcrest:hamcrest-core:1.3 (1 constraints: cc05fe3f)
49-
org.jetbrains:annotations:19.0.0 (1 constraints: 660d8f2c)
50-
org.junit:junit-bom:5.8.2 (12 constraints: 6ac77fbf)
51-
org.junit.jupiter:junit-jupiter:5.8.2 (2 constraints: 260e7a59)
52-
org.junit.jupiter:junit-jupiter-api:5.8.2 (5 constraints: aa4de77d)
53-
org.junit.jupiter:junit-jupiter-engine:5.8.2 (2 constraints: 2117d23c)
54-
org.junit.jupiter:junit-jupiter-migrationsupport:5.8.2 (2 constraints: 260e7a59)
55-
org.junit.jupiter:junit-jupiter-params:5.8.2 (2 constraints: 2117d23c)
56-
org.junit.platform:junit-platform-commons:1.8.2 (3 constraints: ee29ed2b)
57-
org.junit.platform:junit-platform-engine:1.8.2 (4 constraints: 863c7bdc)
58-
org.junit.platform:junit-platform-launcher:1.8.2 (2 constraints: 121b944a)
59-
org.junit.platform:junit-platform-testkit:1.8.2 (1 constraints: 12097995)
60-
org.junit.vintage:junit-vintage-engine:5.8.2 (2 constraints: 260e7a59)
61-
org.objenesis:objenesis:3.1 (2 constraints: bb193de0)
62-
org.opentest4j:opentest4j:1.2.0 (3 constraints: c53224a1)
63-
org.ow2.asm:asm:9.1 (2 constraints: da162012)
48+
org.junit.jupiter:junit-jupiter:5.8.2 (1 constraints: 11051e36)
49+
org.junit.jupiter:junit-jupiter-api:5.8.2 (4 constraints: 95444621)
50+
org.junit.jupiter:junit-jupiter-engine:5.8.2 (1 constraints: 0c0edf3b)
51+
org.junit.jupiter:junit-jupiter-migrationsupport:5.8.2 (1 constraints: 11051e36)
52+
org.junit.jupiter:junit-jupiter-params:5.8.2 (1 constraints: 0c0edf3b)
53+
org.junit.platform:junit-platform-commons:1.8.2 (2 constraints: dd200b4b)
54+
org.junit.platform:junit-platform-engine:1.8.2 (3 constraints: 5e2e6f7f)
55+
org.junit.vintage:junit-vintage-engine:5.8.2 (1 constraints: 11051e36)
56+
org.objenesis:objenesis:2.4 (1 constraints: ea0c8c0a)
57+
org.opentest4j:opentest4j:1.2.0 (2 constraints: cd205b49)
58+
org.ow2.asm:asm:9.1 (1 constraints: 040aa7a4)
6459
org.spockframework:spock-core:2.0-M4-groovy-3.0 (2 constraints: e822d65a)
6560
org.spockframework:spock-junit4:2.0-M4-groovy-3.0 (1 constraints: 25115ddf)

versions.props

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -18,3 +18,4 @@ org.junit.jupiter:* = 5.8.2
1818
org.junit.vintage:* = 5.8.2
1919
org.slf4j:slf4j-api = 1.7.36
2020
com.fasterxml.jackson.*:* = 2.13.2
21+
com.fasterxml.jackson.core:jackson-databind = 2.13.2.1

0 commit comments

Comments
 (0)