Skip to content

deps: Update jackson to address CVE-2026-54515 - #258

Merged
owarai merged 2 commits into
qingstor:masterfrom
owarai:master
Aug 4, 2026
Merged

owarai merged 2 commits into
qingstor:masterfrom
owarai:master

Conversation

@owarai

@owarai owarai commented Aug 4, 2026

Copy link
Copy Markdown
Collaborator

Jackson 2.18.8 is affected by CVE-2026-54515, CVE-2026-59889 and
GHSA-mhm7-754m-9p8w. Update jackson-databind and jackson-dataformat-yaml
to 2.21.5, which reports no known vulnerabilities.

Switch to PropertyNamingStrategies.SNAKE_CASE, which has been available
since 2.12, to replace the deprecated PropertyNamingStrategy constant.

Jackson 2.x keeps a Java 8 baseline, so java8 support is retained.

owarai added 2 commits August 4, 2026 10:19
Jackson 2.18.8 is affected by CVE-2026-54515, CVE-2026-59889 and
GHSA-mhm7-754m-9p8w. Update jackson-databind and jackson-dataformat-yaml
to 2.21.5, which reports no known vulnerabilities.

Switch to PropertyNamingStrategies.SNAKE_CASE, which has been available
since 2.12, to replace the deprecated PropertyNamingStrategy constant.

Jackson 2.x keeps a Java 8 baseline, so java8 support is retained.
@owarai
owarai merged commit 37ed721 into qingstor:master Aug 4, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant