yetanalytics / lrsql

A SQL-based Learning Record Store
https://www.sqllrs.com
Apache License 2.0
91 stars 17 forks source link

Update Cheshire to 5.12.0 #364

Closed vbhayden closed 9 months ago

vbhayden commented 9 months ago

Updates the Cheshire library to 5.12.0 to use the latest version of Jackson.

cliffcaseyyet commented 9 months ago

Hey Trey,

Did this result from a vulnerability scan or something? Our CI did not flag it.

vbhayden commented 9 months ago

Afternoon Cliff,

Yeah, I sent an email with the specifics. The older Jackson versions had a DoS surface that wasn't corrected until 2.15.0, which was flagged as a High vulnerability and blocking a pipeline.