Skip to content

fix: bump jackson-databind to 2.22.3 and submit Gradle dependency graph - #407

Merged
andrii-bodnar merged 1 commit into
masterfrom
fix/bump-jackson-databind
Sep 22, 2026
Merged

andrii-bodnar merged 1 commit into
masterfrom
fix/bump-jackson-databind

Conversation

@andrii-bodnar

Copy link
Copy Markdown
Member

Upgrade jackson-databind from 2.17.3 to 2.22.3 to pick up the fixes for the open Dependabot alerts (CVE-2026-54512, CVE-2026-54513, CVE-2026-68497 and related jackson-core advisories).

Add a dependency-submission workflow so GitHub's dependency graph is built from the actual Gradle dependencies instead of the pom.xml that was removed in 2019, which is what the current alerts still reference.

Upgrade jackson-databind from 2.17.3 to 2.22.3 to pick up the fixes for
the open Dependabot alerts (CVE-2026-54512, CVE-2026-54513,
CVE-2026-68497 and related jackson-core advisories).

Add a dependency-submission workflow so GitHub's dependency graph is
built from the actual Gradle dependencies instead of the pom.xml that
was removed in 2019, which is what the current alerts still reference.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@andrii-bodnar
andrii-bodnar merged commit 98c5525 into master Sep 22, 2026
2 checks passed
@andrii-bodnar
andrii-bodnar deleted the fix/bump-jackson-databind branch September 22, 2026 08:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant