Skip to content

fix: bump jackson to 2.22.3 [IDE-2610] - #469

Merged
rrama merged 1 commit into
mainfrom
fix/IDE-2610_bump-jackson
Oct 1, 2026
Merged

rrama merged 1 commit into
mainfrom
fix/IDE-2610_bump-jackson

Conversation

@nick-y-snyk

@nick-y-snyk nick-y-snyk commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Description

Fixes IDE-2610 (SNYK-JAVA-COMFASTERXMLJACKSONCORE-20059179).

#450 moved Jackson to 2.21.5, which is still vulnerable. The fixed releases are 2.18.11, 2.21.7 and 2.22.3. This PR moves jackson-core and jackson-databind from 2.21.5 to 2.22.3, and jackson-annotations from 2.21 to 2.22, in lockstep. The jar names in plugin/META-INF/MANIFEST.MF and plugin/build.properties change with the pom, since the bundle classpath lists them by exact filename.

The target platform (2.18.0) was also in the vulnerable range and now pins the same versions as the plugin and tests modules.

Are we exposed?

Probably not. The bug is only reachable through JsonFactory.createParser(DataInput). The plugin parses JSON in two places, HTMLSettingsPreferencePage (readTree) and ExecuteCommandBridge (readValue), and both pass a String. This can ship with the next regular release.

Verification

  • snyk test (SCA) on main reports 7 issues, including SNYK-JAVA-COMFASTERXMLJACKSONCORE-20059179 on jackson-core@2.21.5. The same scan on this branch reports 0.
  • The built io.snyk.eclipse.plugin jar bundles jackson-core-2.22.3.jar, jackson-databind-2.22.3.jar and jackson-annotations-2.22.jar.
  • ./mvnw clean verify -pl target-platform,plugin,tests passes: 400 tests, 0 failures.

Checklist

  • Read and understood the Code of Conduct and Contributing Guidelines.
  • Tests added and all succeed (no new tests for a dependency bump; existing 400 pass)
  • Linted (no Java changes, PMD not run)
  • README.md updated, if user-facing

@nick-y-snyk
nick-y-snyk requested review from a team as code owners October 1, 2026 09:37
@snyk-io

snyk-io Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues
✅ Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@snyk-pr-review-bot

Copy link
Copy Markdown

PR Reviewer Guide 🔍

🧪 PR contains tests
🔒 No security concerns identified
⚡ No major issues detected
📚 Repository Context Analyzed

This review considered 14 relevant code sections from 10 files (average relevance: 0.71)

Fixes SNYK-JAVA-COMFASTERXMLJACKSONCORE-20059179 in jackson-core, which
2.21.5 still carries. jackson-core and jackson-databind move from 2.21.5
to 2.22.3 and jackson-annotations from 2.21 to 2.22. The target platform
(2.18.0) was also in the vulnerable range and now pins the same versions.
@nick-y-snyk
nick-y-snyk force-pushed the fix/IDE-2610_bump-jackson branch from ac4818e to ecd66bf Compare October 1, 2026 10:46

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Huh, are these even needed? Screw it, it would take longer to find out than we would ever spend just bumping them as well. 🚢

@rrama
rrama merged commit f35d255 into main Oct 1, 2026
11 checks passed
@rrama
rrama deleted the fix/IDE-2610_bump-jackson branch October 1, 2026 11:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants