Skip to content

Fix Security Violation#438

Open
agrasth wants to merge 2 commits intomasterfrom
violationFix
Open

Fix Security Violation#438
agrasth wants to merge 2 commits intomasterfrom
violationFix

Conversation

@agrasth
Copy link

@agrasth agrasth commented Mar 18, 2026

  • All tests passed. If this feature is not already covered by the tests, I added new tests.
  • This pull request is on the dev branch.

Title: Fix security audit violations - upgrade jackson and netty

Description:
Upgrade vulnerable dependencies to resolve jf audit security violations.

Note on Jackson versions: Using jackson-core/databind 2.21.1 with jackson-annotations 2.21 (mixed patch versions). Both build and audit pass successfully. The 2.15.0 nesting depth fix (CVE-2025-52999/GHSA-h46c-h94j-95f3 from Issue #405) is included in all 2.21.x versions.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant