Skip to content

Conversation

@edwardcapriolo
Copy link
Contributor

No description provided.

@edwardcapriolo
Copy link
Contributor Author

image

@edwardcapriolo edwardcapriolo changed the title Modernize jackson for OSS transien wars Modernize jackson for OSS transient vulnerability Nov 2, 2025
@jasmith-hs
Copy link
Contributor

@jaredstehler @tkindy , any concerns with pushing the jackson version to 2.20.1, beyond 2.18.3 , which is what is used in basepom 65.1?

@jaredstehler
Copy link
Contributor

@jaredstehler @tkindy , any concerns with pushing the jackson version to 2.20.1, beyond 2.18.3 , which is what is used in basepom 65.1?

as long as it doesn't require code changes due to api incompatibilities, i think it should be ok. if we wanted to we could add separate matrix builds for 2.18 and 2.20.

@edwardcapriolo
Copy link
Contributor Author

Ping.

<groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-annotations</artifactId>
<version>2.14.0</version>
<version>2.20</version>
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@edwardcapriolo why 2.20 here versus 2.20.1 elsewhere

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That artifact is not published in cental at the same cadence. There is no 2.20.1

@jasmith-hs jasmith-hs merged commit 0b610c9 into HubSpot:master Nov 18, 2025
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants