Skip to content

Pin jackson to 2.18.11 for dependabot alerts - #62

Merged
stasimus merged 1 commit into
masterfrom
dependabot-fixes
Sep 25, 2026
Merged

stasimus merged 1 commit into
masterfrom
dependabot-fixes

Conversation

@stasimus

@stasimus stasimus commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

play-json 3.0.6 (latest stable) still pulls jackson 2.14.3, which trips the jackson-core and jackson-databind dependabot alerts. Added jackson-core and jackson-databind 2.18.11 as explicit deps so the patched version gets resolved.

Summary by CodeRabbit

  • Chores
    • Updated JSON processing dependencies across several integrations. These changes are not expected to alter user-facing behavior.

@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: evolution-gaming/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 52370b94-783f-408f-aa58-675c4c6d3ecf

📥 Commits

Reviewing files that changed from the base of the PR and between cf934d7 and df15a3e.

📒 Files selected for processing (2)
  • build.sbt
  • project/Dependencies.scala

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The build defines Jackson Core and Databind at version 2.18.11. It adds them to the generic and jsoniter cross-projects, play-json-tools, and play-json-circe.

Changes

Jackson dependency setup

Layer / File(s) Summary
Define and wire Jackson dependencies
project/Dependencies.scala, build.sbt
Defines Jackson Core and Databind at version 2.18.11. Adds both dependencies to the generic and jsoniter cross-projects, play-json-tools, and play-json-circe.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Suggested reviewers: mr-git

Merge Risk: ⚪ Minimal · up to df15a

The dependency update covers the published JVM projects, addressing the reported Jackson version exposure. No material merge risk remains.

Security Architecture Review

Security architecture risk: 🔵 Low · up to df15a

The change is intended to replace older Jackson components with patched versions across four library modules. It does not change a runtime entrypoint or access control, and no new security exposure was established. The versions actually selected by downstream applications remain unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The potentially affected scope is Jackson dependency selection for the four named modules and applications that consume them; the build declarations alone do not establish each application's selected version.

Trust Boundaries and Controls

  • observed — The PR changes build dependency declarations rather than code that accepts untrusted input or enforces a trust boundary.

Hardening Proposals

  • proposed — Verify resolved Jackson versions for each affected JVM module and inspect published dependency metadata and representative downstream resolution before relying on the pin as a security guarantee.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the main change: pinning Jackson to version 2.18.11 to address Dependabot alerts.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@stasimus
stasimus merged commit 487345a into master Sep 25, 2026
12 checks passed
@stasimus
stasimus deleted the dependabot-fixes branch September 25, 2026 19:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant