dstl / baleen

Entity Extraction Text Processor
Apache License 2.0
147 stars 40 forks source link

Update vulnerable dependency: com.fasterxml.jackson.core:jackson-databind #100

Open JavaEcosystemStudy opened 2 years ago

JavaEcosystemStudy commented 2 years ago

Hi! We spot a vulnerable dependency in your project, which might threaten your software. We also found another project that uses the same vulnerable dependency in a similar way as you did, and they have upgraded the dependency. We, thus, believe that your project is highly possible to be affected by this vulnerability similarly. The following shows the detailed information.

Vulnerability description

Upgrade example

Another project also used the same dependency with a similar invocation path, and they have taken actions to resolve this issue.

Therefore, you might also need to upgrade this dependency. Hope this can help you! 😄