Skip to content

build: Bump jackson-databind from 2.21.2 to 2.21.4 - #911

Closed
mc-nv wants to merge 1 commit into
mainfrom
mchornyi/bump-jackson-databind-2.21.4
Closed

build: Bump jackson-databind from 2.21.2 to 2.21.4#911
mc-nv wants to merge 1 commit into
mainfrom
mchornyi/bump-jackson-databind-2.21.4

Conversation

@mc-nv

@mc-nv mc-nv commented Jul 18, 2026

Copy link
Copy Markdown
Contributor

What does the PR do?

Bumps com.fasterxml.jackson.core:jackson-databind from 2.21.2 to 2.21.4 in the Java client. The 26.07 SDK container security scan (Pulse) flags two HIGH advisories against jackson-databind bundled into the Java example fat-JARs (SimpleInferClient.jar, SimpleInferPerf.jar, MemoryGrowthTest.jar):

Related Issues / PRs

Test plan

  • One-line dependency version bump; examples are rebuilt by the SDK container build.
  • Verification: for 26.07: rebuild the SDK container and re-run the scan-container:py3-sdk security job, which currently fails on these two advisories (internal pipeline 58029553, job 365259903).

Caveats

The remaining findings in the scan report (Go stdlib CVEs in the CUDA Nsight Systems nic_sampler plugin) are third-party toolkit content covered by a temporary GlobalVEX and are not addressable in this repo.

Checklist

  • PR title follows <commit_type>: <Title> (conventional commit — enforced by the conventional-pre-commit hook)
  • I ran pre-commit install && pre-commit run --all-files locally and it passes
  • Copyright header is correct on all changed files
  • External contributors: I have read the Contribution guidelines and signed the Contributor License Agreement

@mc-nv mc-nv self-assigned this Jul 18, 2026
@mc-nv

mc-nv commented Jul 18, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #908, which already includes this jackson-databind bump on main alongside the broader gRPC v1.81.1 dependency alignment. The r26.07 backport continues in #910.

@mc-nv mc-nv closed this Jul 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant