Skip to content

GEODE-10567: Security Vulnerability Remediation for Jackson and Dependency Updates#7991

Open
JinwooHwang wants to merge 1 commit intoapache:support/1.15from
JinwooHwang:feature/GEODE-10567
Open

GEODE-10567: Security Vulnerability Remediation for Jackson and Dependency Updates#7991
JinwooHwang wants to merge 1 commit intoapache:support/1.15from
JinwooHwang:feature/GEODE-10567

Conversation

@JinwooHwang
Copy link
Contributor

Summary

This PR upgrades Jackson dependencies and updates related integration test resources to ensure compatibility and correctness for GEODE-10567.

Background

Jackson is a widely used library for JSON processing in Java. Keeping it up to date is important for security, performance, and compatibility. This change updates Jackson and related dependencies, and ensures all integration test resources reflect the new versions.

Changes

  • boms/geode-all-bom/src/test/resources/expected-pom.xml
    • Updated expected Maven POM to reflect new Jackson versions and dependency changes.
  • build-tools/geode-dependency-management/src/main/groovy/org/apache/geode/gradle/plugins/DependencyConstraints.groovy
    • Upgraded Jackson and related dependency versions in Gradle plugin constraints.
  • geode-assembly/src/integrationTest/resources/assembly_content.txt
    • Updated list of files included in the assembly for integration tests.
  • geode-assembly/src/integrationTest/resources/gfsh_dependency_classpath.txt
    • Updated GFSH dependency classpath for integration tests to match new dependency versions.
  • geode-server-all/src/integrationTest/resources/dependency_classpath.txt
    • Updated server dependency classpath for integration tests to match new dependency versions.

Related

  • Jira: GEODE-10567

For all changes, please confirm:

  • Is there a JIRA ticket associated with this PR? Is it referenced in the commit message?
  • Has your PR been rebased against the latest commit within the target branch (typically develop)?
  • Is your initial contribution a single, squashed commit?
  • Does gradlew build run cleanly?
  • Have you written or updated unit tests to verify your changes?
  • If adding new dependencies to the code, are these dependencies licensed in a way that is compatible for inclusion under ASF 2.0?

@JinwooHwang JinwooHwang requested a review from marinov-code March 4, 2026 14:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant