jenkinsci / jenkinsci/java-client-api

Please release a new version.

Offen
#454 6 Kommentare 7 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
Java
Sterne
913
Forks
466
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

First off thanks for all the work that has gone into this library! Currently, the latest release of `java-client-api` is `0.3.8`. It depends on `com.fasterxml.jackson.core:jackson-databind:2.3.4`, which has several vulnerabilities – see the [GitHub Advisory Database](https://github.com/advisories?query=%22jackson-databind%22) I expect that most, if not all, vulnerabilities are irrelevant in context of `java-client-api`. But nevertheless I would like to ask you to release a new version of `java-client-api`, which depends on a newer version of `com.fasterxml.jackson.core:jackson-databind`. I see that the current pom.xml references `com.fasterxml.jackson.core:jackson-databind:2.9.9`, which has much less vulnerabilities, and there is [PR #450](https://github.com/jenkinsci/java-client-api/pull/450), which suggests to bump `jackson-databind.version` to `2.10.3`. At work, we are using OWASP Dependency Check to scan Java projects to identify the use of known vulnerable components. It reports that one of my projects uses a component that has known critical vulnerabilities. The reason for that is that the respective project depends on `java-client-api:0.3.8`, which depends on `com.fasterxml.jackson.core:jackson-databind:2.3.4`. I saw that [Milestone 0.4.0](https://github.com/jenkinsci/java-client-api/milestone/11) is 79% complete. Is it necessary to close of all of the remaining open issues? Which ones are the most important ones?

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Start by reviewing pom.xml and PR #450, then check the remaining work in milestone 0.4.0. Confirm which jackson-databind version should ship and identify the release prerequisites; done means a new java-client-api version no longer depends on 2.3.4.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
java
Bereich
release, security
Issue-Typ
Feature
Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Aktivitätsstatus
Veraltet
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
30/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.