Upgrade jackson to 2.9.8
There is a vulerability in prior versions, per the following CVE: https://nvd.nist.gov/vuln/detail/CVE-2018-1000873
This commit is contained in:
parent
d4cdcf0fc8
commit
a620983fb1
|
@ -7,8 +7,7 @@ ext {
|
|||
|
||||
slf4j : "1.7.25",
|
||||
guava : "20.0", // Last version to support Java 7
|
||||
jackson : "2.6.3", // This is a transitive dependency for the tracer.
|
||||
// Use an old version to not force an upgrade for others using tracer as a dependency.
|
||||
jackson : "2.9.8", // https://nvd.nist.gov/vuln/detail/CVE-2018-1000873
|
||||
|
||||
spock : "1.2-groovy-$spockGroovyVer",
|
||||
groovy : groovyVer,
|
||||
|
|
Loading…
Reference in New Issue