Skip to content

fix(security): bump Jackson to 2.21 LTS line - #161

Merged
alexgomezlf merged 11 commits into
v2from
alex/bump-jackson-2.21-lts
Sep 2, 2026
Merged

alexgomezlf merged 11 commits into
v2from
alex/bump-jackson-2.21-lts

Conversation

@alexgomezlf

Copy link
Copy Markdown
Contributor

Remediates CVE-2026-59889 (JsonView authorization bypass) in jackson-databind. Targets the 2.21 LTS line rather than the latest 2.22.x release for long-term stability in this client library.

jackson-annotations no longer publishes patch-level versions past 2.20, so it now has its own jackson-annotations-version property separate from the shared jackson-version used by jackson-core and jackson-databind.

Remediates CVE-2026-59889 (JsonView authorization bypass) in
jackson-databind. Targets the 2.21 LTS line rather than the latest
2.22.x release for long-term stability in this client library.

jackson-annotations no longer publishes patch-level versions past
2.20, so it now has its own jackson-annotations-version property
separate from the shared jackson-version used by jackson-core and
jackson-databind.
Picks up the newly published lf-api-client-core 2.2.5, which
includes the Jackson 2.21 LTS bump, keeping both packages on a
consistent Jackson version.
CI overrides the checked-in pom.xml version via
mvn versions:set using VERSION_PREFIX from main.yml, so bumping
pom.xml's <version> directly had no effect on the published
artifact. Reverted pom.xml to its 1.0.0 placeholder and bumped
VERSION_PREFIX to 1.0.4 instead, matching the fix applied in
lf-api-client-core-java (PR #89).
Default GITHUB_TOKEN permissions are read-only, so
EnricoMi/publish-unit-test-result-action was failing with 403
Resource not accessible by integration when creating check runs
(and would also fail posting its PR comment). Same fix already
worked out on an earlier abandoned branch, carried over here.
@github-actions

github-actions Bot commented Aug 26, 2026 •

Copy link
Copy Markdown
Contributor

unit-test-results

25 tests  ±0   25 ✅ ±0   0s ⏱️ ±0s
 3 suites ±0    0 💤 ±0 
 3 files   ±0    0 ❌ ±0 

Results for commit d30e9a9. ± Comparison against base commit 50913c6.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Aug 26, 2026 •

Copy link
Copy Markdown
Contributor

integration-test-results-cloud

77 tests  ±0   76 ✅ +3   2m 28s ⏱️ - 1m 46s
16 suites ±0    1 💤 ±0 
16 files   ±0    0 ❌  - 2 

Results for commit d30e9a9. ± Comparison against base commit 50913c6.

♻️ This comment has been updated with latest results.

alexandria.gomez and others added 7 commits August 26, 2026 13:50
startDeleteEntryCanDeleteFolder only waited for the task to leave
IN_PROGRESS, which is also true when a task fails, then asserted
getEntry throws 404. A failed delete (e.g. a required audit reason
not set) would silently look identical to "not deleted yet" in the
old assertion. Now asserts TaskStatus.COMPLETED first and prints
the ProblemDetails on failure, matching the pattern already used in
ImportUploadedPartsApiTest.
REPOSITORY_ID_1 requires an audit reason for DeleteEntry
(ErrorCode 216: "Need to provide correct audit reason for
DeleteEntry"), confirmed via the ProblemDetails now printed by
startDeleteEntryCanDeleteFolder. Every StartDeleteEntryRequest in
the suite was missing one, including BaseTest.deleteEntry(), the
shared @afterall cleanup helper used by nearly every test class,
which was silently failing and leaving orphaned test folders behind.

Added findAuditReasonForDelete()/newDeleteEntryRequest() to
BaseTest, mirroring the existing findAuditReasonForExport() pattern
in ImportUploadedPartsApiTest, and switched all four delete call
sites to use it.

@bzajzon-laserfiche bzajzon-laserfiche left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving. The Jackson change is sound and the split property is well justified: pinning jackson-annotations separately at 2.21 while jackson-core/jackson-databind track 2.21.6 is the normal arrangement once annotations stops cutting patch releases, and the body explains why.

Two things I'd like reflected in the description rather than changed in the code, since a reader coming to this from the title will not expect them.

The PR does more than bump Jackson. Alongside the CVE fix it also bumps lf-api-client-core 2.2.4 → 2.2.5, bumps VERSION_PREFIX to 1.0.4, adds a permissions block to build-n-test, switches the integration-test repository, and reworks delete-entry test setup. The changelog covers the two dependency bumps; the rest is invisible unless you read the diff.

The test repository switch is the one worth calling out. DEV_CA_PUBLIC_USE_REPOSITORY_ID_2 → _1 changes which repository every integration test runs against, and the BaseTest changes look like the consequence — repository 1 appearing to require an audit reason on delete where 2 did not. If that is the reason, it belongs in the description, because it is the change most likely to confuse someone bisecting a future CI failure. Unrelated to the CVE either way.

Two things I liked. The explicit permissions block is a tightening, not a loosening, since the default would otherwise be broader. And asserting TaskStatus.COMPLETED with printProblemDetails on failure is a real improvement over waiting and inferring success from the entry being gone — the old shape would report a deletion that silently failed as a passing test.

One small note, not blocking: newDeleteEntryRequest() falls back to a request with no audit reason when none is found, which keeps this working on repositories that do not require one. That is the right default, but it does mean a misconfigured fixture surfaces as a delete failure later rather than at setup.

@alexgomezlf
alexgomezlf merged commit 8218848 into v2 Sep 2, 2026
9 checks passed
@alexgomezlf
alexgomezlf deleted the alex/bump-jackson-2.21-lts branch September 2, 2026 17:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants