Conversation
…ml to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924
|
This update includes a minor version bump for springdoc-openapi-ui 1.6.14 → 1.7.0Risk: Medium This upgrade to version Potential Breaking Change: Recommendation: com.fasterxml.jackson.datatype:jackson-datatype-jsr310 2.13.4 → 2.18.6Risk: Low This is a minor version upgrade within the same major series. The release notes for Jackson 2.18 do not indicate any breaking API changes for the
|
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
Snyk has created this PR to fix 1 vulnerabilities in the maven dependencies of this project.
Snyk changed the following file(s):
samples/openapi3/client/petstore/spring-cloud-oas3-fakeapi/pom.xmlVulnerabilities that will be fixed with an upgrade:
SNYK-JAVA-COMFASTERXMLJACKSONCORE-15365924
1.6.14->1.7.0No Path FoundProof of ConceptBreaking Change Risk
Vulnerabilities that could not be fixed
com.fasterxml.jackson.datatype:jackson-datatype-jsr310@2.13.4tocom.fasterxml.jackson.datatype:jackson-datatype-jsr310@2.18.6; Reasoncould not apply upgrade, dependency is managed externally; Location:https://maven-central.storage-download.googleapis.com/maven2/com/fasterxml/jackson/jackson-bom/2.13.4.20221013/jackson-bom-2.13.4.20221013.pomImportant
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Allocation of Resources Without Limits or Throttling