Skip to content

Bump com.fasterxml.jackson:jackson-bom from 2.22.1 to 2.22.2 - #188

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/maven/com.fasterxml.jackson-jackson-bom-2.22.2
Open

Bump com.fasterxml.jackson:jackson-bom from 2.22.1 to 2.22.2#188
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/maven/com.fasterxml.jackson-jackson-bom-2.22.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown
Contributor

Bumps com.fasterxml.jackson:jackson-bom from 2.22.1 to 2.22.2.

Commits
  • 062d76d [maven-release-plugin] prepare release jackson-bom-2.22.2
  • dcf18f7 Prep for 2.22.2 release
  • 9688c7b Merge branch '2.21' into 2.22
  • 7796a7d Merge branch '2.20' into 2.21
  • d3cd7fc Merge branch '2.19' into 2.20
  • 7a28068 Merge branch '2.18' into 2.19
  • 51eb465 Post-release dep version bump
  • 34ff5e8 [maven-release-plugin] prepare for next development iteration
  • 0b44a45 [maven-release-plugin] prepare release jackson-bom-2.18.10
  • 691ec93 Prep for 2.18.10 release
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [com.fasterxml.jackson:jackson-bom](https://github.com/FasterXML/jackson-bom) from 2.22.1 to 2.22.2.
- [Commits](FasterXML/jackson-bom@jackson-bom-2.22.1...jackson-bom-2.22.2)

---
updated-dependencies:
- dependency-name: com.fasterxml.jackson:jackson-bom
  dependency-version: 2.22.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Aug 24, 2026
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@github-actions

Copy link
Copy Markdown
Contributor

Mend Scan Results

Status: ⚠️ Findings detected

⚠️ SCA findings detected

SCA scan output



Identified 44 dependencies

Detected 1 vulnerability (0 Critical, 1 High, 0 Medium, 0 Low)

+----------+---------------------------+----------------+---------------------------------------------------------+
| SEVERITY |          LIBRARY          |       ID       |                         TOP FIX                         |
+----------+---------------------------+----------------+---------------------------------------------------------+
| HIGH     | logback-classic-1.6.1.jar | CVE-2026-19880 | Upgrade to version ch.qos.logback:logback-classic:1.6.3 |
+----------+---------------------------+----------------+---------------------------------------------------------+


Paths at risk

P = policy violation
MSC = malicious vulnerability
CRITICAL/HIGH/MEDIUM/LOW = vulnerability severity

npm-manipulator-cli-1.3.5-SNAPSHOT.jar
|-- logback-classic-1.6.1.jar [1 HIGH]
|-- npm-manipulator-core-1.3.5-SNAPSHOT.jar
	|-- logback-classic-1.6.1.jar [1 HIGH]
|-- npm-manipulator-npm-1.3.5-SNAPSHOT.jar
	|-- logback-classic-1.6.1.jar [1 HIGH]
	|-- atlas-npm-identities-1.2.2.jar
		|-- logback-classic-1.6.1.jar [1 HIGH]
		|-- atlas-identities-1.2.2.jar
			|-- logback-classic-1.6.1.jar [1 HIGH]
npm-manipulator-core-1.3.5-SNAPSHOT.jar
|-- logback-classic-1.6.1.jar [1 HIGH]
npm-manipulator-npm-1.3.5-SNAPSHOT.jar
|-- logback-classic-1.6.1.jar [1 HIGH]
|-- atlas-npm-identities-1.2.2.jar
	|-- logback-classic-1.6.1.jar [1 HIGH]
	|-- atlas-identities-1.2.2.jar
		|-- logback-classic-1.6.1.jar [1 HIGH]
|-- npm-manipulator-core-1.3.5-SNAPSHOT.jar
	|-- logback-classic-1.6.1.jar [1 HIGH]


No Policy violations were detected

Project 'npm-manipulator' was updated, for more information, visit the Mend platform: https://ibmets.whitesourcesoftware.com/app/orgs/Enterprise%20Applications/applications/summary?project=c76f1ac2-8d55-4416-86f7-e1cfc7949dfa
Or the Core UI: https://ibmets.whitesourcesoftware.com/Wss/WSS.html#!project;token=b8481532debe418b91fc637a46d8feef13fffac54c864f1597b7ff1f8571ad38

Mend AI scan succeeded.

Support Token: 3b50e37da3b03486caa4248167bb586e31787583849792
SAST scan output
*no findings*

Full logs and artifacts

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant