Skip to content

Conversation

@predic8
Copy link
Member

@predic8 predic8 commented Feb 9, 2026

snyk-top-banner

Snyk has created this PR to upgrade com.fasterxml.jackson.core:jackson-core from 2.20.1 to 2.21.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 2 versions ahead of your current version.

  • The recommended version was released 21 days ago.


Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

….21.0

Snyk has created this PR to upgrade com.fasterxml.jackson.core:jackson-core from 2.20.1 to 2.21.0.

See this package in maven:
com.fasterxml.jackson.core:jackson-core

See this project in Snyk:
https://app.snyk.io/org/predic8/project/ba8f26a2-ffb6-4476-8bc3-8c1da9297ba4?utm_source=github&utm_medium=referral&page=upgrade-pr
…m 2.20.1 to 2.21.0

Snyk has created this PR to upgrade com.fasterxml.jackson.datatype:jackson-datatype-joda from 2.20.1 to 2.21.0.

See this package in maven:
com.fasterxml.jackson.datatype:jackson-datatype-joda

See this project in Snyk:
https://app.snyk.io/org/predic8/project/ba8f26a2-ffb6-4476-8bc3-8c1da9297ba4?utm_source=github&utm_medium=referral&page=upgrade-pr
…rom 2.20.1 to 2.21.0

Snyk has created this PR to upgrade com.fasterxml.jackson.datatype:jackson-datatype-jsr310 from 2.20.1 to 2.21.0.

See this package in maven:
com.fasterxml.jackson.datatype:jackson-datatype-jsr310

See this project in Snyk:
https://app.snyk.io/org/predic8/project/ba8f26a2-ffb6-4476-8bc3-8c1da9297ba4?utm_source=github&utm_medium=referral&page=upgrade-pr
@coderabbitai
Copy link
Contributor

coderabbitai bot commented Feb 9, 2026

Important

Review skipped

Ignore keyword(s) in the title.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch snyk-upgrade-70336afdec98d448aaaef2a78d22bf2a

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@membrane-ci-server
Copy link

This pull request needs "/ok-to-test" from an authorized committer.

snyk-bot and others added 3 commits February 9, 2026 08:03
…to 2.21.0

Snyk has created this PR to upgrade com.fasterxml.jackson.core:jackson-databind from 2.20.1 to 2.21.0.

See this package in maven:
com.fasterxml.jackson.core:jackson-databind

See this project in Snyk:
https://app.snyk.io/org/predic8/project/91636bd9-e5c1-4790-a702-08506baeb26c?utm_source=github&utm_medium=referral&page=upgrade-pr
… from 2.20.1 to 2.21.0

Snyk has created this PR to upgrade com.fasterxml.jackson.dataformat:jackson-dataformat-yaml from 2.20.1 to 2.21.0.

See this package in maven:
com.fasterxml.jackson.dataformat:jackson-dataformat-yaml

See this project in Snyk:
https://app.snyk.io/org/predic8/project/91636bd9-e5c1-4790-a702-08506baeb26c?utm_source=github&utm_medium=referral&page=upgrade-pr
@christiangoerdes
Copy link
Collaborator

/ok-to-test

predic8 and others added 4 commits February 11, 2026 09:14
The upgrade to Jackson 2.21.0 caused a NoClassDefFoundError in
YAMLBeanParsingTest because jackson-annotations remained at version 2.20.
Jackson 2.21.0 uses version 2.21 for annotations (no .0 suffix).

This change introduces jackson-bom in the root pom.xml's
dependencyManagement to handle these discrepancies automatically and
ensure all Jackson modules are aligned. Explicit version overrides
for core Jackson modules have been removed from sub-modules to let the
BOM manage them.

Co-authored-by: rrayst <508061+rrayst@users.noreply.github.com>
@rrayst rrayst merged commit 81b5501 into master Feb 11, 2026
5 checks passed
@rrayst rrayst deleted the snyk-upgrade-70336afdec98d448aaaef2a78d22bf2a branch February 11, 2026 15:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants