Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

How can i upgrade the jackson-databin jar version that included in the shade jar htrace-core4 #914

Open
Eason897 opened this issue Apr 4, 2024 · 2 comments

Comments

@Eason897
Copy link

Eason897 commented Apr 4, 2024

Please check the User Guide before submitting "how do I do 'x'?" questions!

Shadow Version

4.0.0

Gradle Version

4.10.3

Expected Behavior:

I want to upgrade the jackson databin version in the htrace-core4:4.1.0-incubating jar package, which is an uber jar. The renamed jackson databin version is 2.4.0, which contains a high-risk vulnerability. For example, CVE-2017-17485.I want to upgrade the jackson databin to version 2.15.2.

Actual Behavior

I don't know how to do it

Gradle Build Script(s)

Content of Shadow JAR (jar tf <jar file> - post link to GIST if too long)

@Eason897
Copy link
Author

Eason897 commented Apr 4, 2024

20240404-155640

@Eason897
Copy link
Author

Eason897 commented Apr 4, 2024

maven can handle like this:
20240404-161003

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant