-
-
Notifications
You must be signed in to change notification settings - Fork 4.1k
Jackson 2.15.4 (was 2.14.3) #12440
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Jackson 2.15.4 (was 2.14.3) #12440
Conversation
|
Can fix playframework/play-ebean#423 and unblock playframework/play-ebean#438 |
|
Will investigate later... |
|
Also nightly test fail because they use pekko snapshots which already upgraded jackson: |
|
The equivalent upgrade in Pekko - apache/pekko#564 Also linking playframework/play-json#1055 |
Jackson now has a default max depth of 1000. apache/pekko#564 supports a config that lets users override this max depth. @mkurz would you be interested in supporting a similar set of configs in Play? |
In order to avoid conflicts with Play's Jackson dependency and fix error: ``` com.fasterxml.jackson.databind.JsonMappingException: Scala module 2.14.3 requires Jackson Databind version >= 2.14.0 and < 2.15.0 - Found jackson-databind version 2.17.2 ``` Play needs to adjust some code for its next major release to correctly support Jackson 2,17, see: playframework/playframework#12440 Co-authored-by: Matthias Kurz <[email protected]>
I think you can override the jackson dependencies in the following way in your After a reload, the output of
should contain following lines |
|
I am a Jackson contributor. Neither of the 2 issues affect play/play-json. |
Here is another in-depth answer I gave a while ago regarding this "severity vulnerability". |
|
Closing as this is part of |
Step by step.
Akka bumped already, seems everything went smoothly:
Upgrade to 2.16 will be done in: