org.codehaus.jackson:jackson-mapper-asl is not maintained and has a serious CVE
Open
- Dominant language
- Java
- Stars
- 6.1k
- Forks
- 1.5k
- Avg merge
- 1d 21h
- Merged PRs (30d)
- 189
Description
[org.codehaus.jackson:jackson-mapper-asl](https://github.com/advisories/GHSA-r6j9-8759-g62w)
it should be easy to switch to jackson 2.x - very similar api
Contributor guide
Research direction
Start by locating the dependency declarations and usages of org.codehaus.jackson:jackson-mapper-asl, then review the Jackson 2.x compatibility needs described in the issue. Check the affected build and tests after the dependency migration; done means the vulnerable dependency is removed and the project still passes its relevant tests.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- backend, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100