From df44fdc8a52f12d61defa4354e3ee6c203b91afe Mon Sep 17 00:00:00 2001 From: Manu Zhang Date: Fri, 2 Oct 2026 10:28:24 +0800 Subject: [PATCH] Bump jackson.version from 2.22.2 to 2.22.3 Jackson 2.22.2, which parquet-jackson shades, is affected by CVE-2026-89407 and CVE-2026-89425 in jackson-core. Both are fixed in 2.22.3. Generated-by: Claude Code Co-Authored-By: Claude Opus 5.5 --- pom.xml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pom.xml b/pom.xml index ebb7fbd849..fd56279cb8 100644 --- a/pom.xml +++ b/pom.xml @@ -75,8 +75,8 @@ com.fasterxml.jackson.datatype com.fasterxml.jackson - 2.22.2 - 2.22.2 + 2.22.3 + 2.22.3 2.22 0.26.2 1.3.2