Bump jackson-bom to 2.21.4 to fix CVEs#1412
Conversation
…517/54518 jackson-databind 2.21.4 fixes 6 CVEs detected by the Trivy image scan. CVE-2026-54515 is suppressed as no fix exists in the 2.21.x line yet (Trivy DB references 2.21.5 which has not been released). Also removes expired Netty CVE suppressions (already fixed by the 4.1.135.Final bump in #1389).
|
Claude finished @vastin's task in 1m 24s —— View job Claude PR Review
LGTM — small, focused, well-justified change. No blocking issues. Verified:
Minor observations (non-blocking):
|
Summary
jackson-bomfrom 2.21.1 → 2.21.4, fixing CVE-2026-54512, CVE-2026-54513, CVE-2026-54514, CVE-2026-54516, CVE-2026-54517, CVE-2026-54518 (release notes)Test plan