Skip to content

Conversation

@senthh
Copy link

@senthh senthh commented Sep 4, 2024

What changes were proposed in this pull request?

Upgrade snakeyaml version to 2.0

We have jackson 2.14. And as per opensource PR [SPARK-43263][BUILD] Upgrade FasterXML jackson to 2.15.0 by bjornjorgensen · Pull Request #40933 · apache/spark , if we have jackson 2.14.2 then we can directly upgrade snakeyaml to 2.0 without any other changes. I m upgrading both jackson and snakeyaml to 2.14.2 and 2.0 respectively.

Why are the changes needed?

Upgrade snakeyaml to 2.0 to fix below CVEs,

CVE-2022-38751
CVE-2022-38752
CVE-2022-41854
CVE-2022-1471

Does this PR introduce any user-facing change?

No

@github-actions github-actions bot added the BUILD label Sep 4, 2024
@senthh senthh merged commit 02b3f43 into ODP-2049 Sep 4, 2024
@prabhjyotsingh prabhjyotsingh deleted the ODP-2187 branch September 27, 2024 12:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants