yykaue opened a new pull request, #6970:
URL: https://github.com/apache/shenyu/pull/6970

   ## What this PR does
   
   - Upgrade the `shenyu-e2e` Jackson BOM from `2.13.3` to `2.15.3`.
   - Align the E2E Jackson version with the root POM.
   - Avoid the vulnerable `jackson-databind` version affected by CVE-2022-42003 
and CVE-2022-42004.
   
   ## Testing
   
   - All 15 `shenyu-e2e` modules passed Maven validation.
   - All relevant unit tests passed: 5 tests, 0 failures, 0 errors.
   - Main and test sources of all 15 modules compiled successfully.
   - Jackson Core, Databind, and Annotations were confirmed to resolve to 
`2.15.3`.
   
   Fixes #6599
   
   @Aias00 Could you please help review this PR? Thank you!


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to