From c8edd801e208edc2fc3f786495d66379bf7928f3 Mon Sep 17 00:00:00 2001 From: Mark Symons Date: Sun, 15 Sep 2019 15:06:42 +0100 Subject: [PATCH] [JENKINS-59379] Update jackson via BOM import * Change property name from jackson-databind.version to jackson.version * Replace jackson modules in dependencyManagement by jackson-bom POM import * Use version 2.9.9.20190807. This gives jackson-databind 2.9.9.3 with fixes for four CVE --- pom.xml | 21 ++++++--------------- 1 file changed, 6 insertions(+), 15 deletions(-) diff --git a/pom.xml b/pom.xml index 68704676..c26339f1 100644 --- a/pom.xml +++ b/pom.xml @@ -62,7 +62,7 @@ 4.5.8 4.4.11 4.5.8 - 2.9.9 + 2.9.9.20190807 @@ -88,20 +88,11 @@ - com.fasterxml.jackson.core - jackson-annotations - ${jackson-databind.version} - - - com.fasterxml.jackson.core - jackson-core - ${jackson-databind.version} - - - - com.fasterxml.jackson.core - jackson-databind - ${jackson-databind.version} + com.fasterxml.jackson + jackson-bom + ${jackson.version} + pom + import