Uploaded image for project: 'Hadoop Common'
  1. Hadoop Common
  2. HADOOP-16485 Remove dependency on jackson
  3. HADOOP-16905

Update jackson-databind to 2.10.3 to relieve us from the endless CVE patches

    XMLWordPrintableJSON

Details

    • Reviewed

    Description

      Jackson-databind 2.10 should relieve us from the endless CVE patches according to https://medium.com/@cowtowncoder/jackson-2-10-features-cd880674d8a2

      Not sure if this is an easy update, but i think we should do this in the Hadoop 3.3.0 and before removing jackson-databind entirely.

      Attachments

        Issue Links

          Activity

            People

              weichiu Wei-Chiu Chuang
              weichiu Wei-Chiu Chuang
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 5h 10m
                  5h 10m