samza icon indicating copy to clipboard operation
samza copied to clipboard

SAMZA-2758: Upgrade vulnerable versions jetty and jackson

Open perkss opened this issue 2 years ago • 1 comments

Issues: Upgrade dependencies for security fixes and enhancements for jetty and jackson

In current dependencies there are security vulnerabilities

Jackson: https://security.snyk.io/package/maven/com.fasterxml.jackson.core:jackson-databind/2.12.2

Jetty: https://security.snyk.io/package/maven/org.eclipse.jetty:jetty-server/9.4.38.v20210224

Upgrade Jackson to version: 2.13.3

Upgrade Jetty to 9.4.48.v20220622

Changes: Describe major changes, listing each separately.

Upgraded dependency management versions Tests: Existing Tests API Changes: None Upgrade Instructions: None Usage Instructions: None

perkss avatar Aug 20 '22 07:08 perkss

@Sanil15 @mynameborat can you please take a look

perkss avatar Aug 20 '22 18:08 perkss

@perkss Have you tested with deploying jobs on top of the existing tests?

mynameborat avatar Sep 13 '22 17:09 mynameborat

@mynameborat yeah tested against local jobs that I run as samples

perkss avatar Sep 19 '22 14:09 perkss