HADOOP-16905. Update jackson-databind to 2.10.3 to relieve us from the endless CVE patches. (#1876)

This commit is contained in:
Wei-Chiu Chuang 2020-03-06 19:18:01 -08:00 committed by GitHub
parent 4062217189
commit 69faaa1d58
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
2 changed files with 9 additions and 2 deletions

View File

@ -339,6 +339,13 @@
<exclude>**/pom.xml</exclude>
</excludes>
</relocation>
<relocation>
<pattern>javax/xml/bind/</pattern>
<shadedPattern>${shaded.dependency.prefix}.javax.xml.bind.</shadedPattern>
<excludes>
<exclude>**/pom.xml</exclude>
</excludes>
</relocation>
<relocation>
<pattern>net/</pattern>
<shadedPattern>${shaded.dependency.prefix}.net.</shadedPattern>

View File

@ -71,8 +71,8 @@
<!-- jackson versions -->
<jackson.version>1.9.13</jackson.version>
<jackson2.version>2.9.10</jackson2.version>
<jackson2.databind.version>2.9.10.3</jackson2.databind.version>
<jackson2.version>2.10.3</jackson2.version>
<jackson2.databind.version>2.10.3</jackson2.databind.version>
<!-- httpcomponents versions -->
<httpclient.version>4.5.6</httpclient.version>