vavr-io / vavr-jackson

Jackson datatype module for Vavr
Apache License 2.0
97 stars 35 forks source link

Update Dependencies: Transitive vulnerable dependency jackson-databind #192

Open superduper opened 1 year ago

superduper commented 1 year ago

Hi!

I've noticed quite a long list of CVEs associated with one of dependencies that 0.10.3 relies on. Do you think it's safe to simply bump version to a non-vulnerable one?

image