Fix Security vulnerability with jackson dependency #53
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
The version 0.2.6 of jackson-databind-nullable dependency has high vulnerability to DOS (Denial of Service) attacks. It has been identified during the scanning with synk security tool. Hence we are changing it to a version 2.12.7.1 which has been identified as a more secure version by synk.
Built jar with java 8 and pushed to cb-app and ran the regression
cbapp PR - https://chargebee.slack.com/archives/C03NKLVB2EA/p1733566316804839
Built jar with java 17, imported it to cb-taxadapter-service locally, ran units and integrations test cases. All passing. Attaching the files.
mvn_clean_uts.txt
mvn_compile_9thDec.txt
Uploading mvn_integration_test_results_9thDec.txt…