vavr-io / vavr-jackson

Jackson datatype module for Vavr
Apache License 2.0
97 stars 35 forks source link

Jackson dependency update #199

Open gsvdutra opened 1 year ago

gsvdutra commented 1 year ago

The Jackson package causes reliability issues because of a vulnerability.

The version 2.14.2 is vulnerable to Denial of Service (DoS).

This can be fixed by updating the library to 2.15.0

https://security.snyk.io/package/maven/com.fasterxml.jackson.core:jackson-databind