jenkinsci / allure-plugin

Allure Jenkins Plugin
https://plugins.jenkins.io/allure-jenkins-plugin/
Other
84 stars 63 forks source link

Update jackson-databind version due to security vulnerabilities #287

Closed aptester closed 2 years ago

aptester commented 3 years ago

Due to reported security vulnerabilities with jackson-databind, it should be updated to 2.12.3 that was done here : https://github.com/allure-framework/allure2/pull/1212

https://blog.sonatype.com/jackson-databind-the-end-of-the-blacklist https://github.com/advisories/GHSA-288c-cq4h-88gq https://github.com/advisories/GHSA-f3j5-rmmp-3fc5

aptester commented 3 years ago

@eroshenkoam Can this be fixed? Or should I submit a PR?