IBM / cics-bundle-maven

The plugin to build and deploy CICS bundles in a Maven build.
https://ibm.github.io/cics-bundle-maven/plugin-info.html
Eclipse Public License 2.0
18 stars 25 forks source link

Update dependency to avoid jackson-databind CVEs #52

Closed ind1go closed 5 years ago

ind1go commented 5 years ago

Having been alerted to a vulnerability by Dependabot, this pull request updates to the later security fix.

ind1go commented 5 years ago

I'm not particularly inclined because the vulnerabilities are not in bits of jackson-databind that we use, it's just that if our plugin is being scanned by consumers it may flag up the CVEs. I think we could probably wait a little while and produce a more worthwhile 0.0.2.