From f1c7eed49e7e850459a951658b84943af6e8eed9 Mon Sep 17 00:00:00 2001 From: CentOS Sources Date: Tue, 28 Apr 2020 04:49:44 -0400 Subject: [PATCH] import jackson-databind-2.10.0-1.module+el8.2.0+5059+3eb3af25 --- .gitignore | 2 +- .jackson-databind.metadata | 2 +- SPECS/jackson-databind.spec | 22 ++++++++++++++++------ 3 files changed, 18 insertions(+), 8 deletions(-) diff --git a/.gitignore b/.gitignore index 17a8657..ee5f0d8 100644 --- a/.gitignore +++ b/.gitignore @@ -1 +1 @@ -SOURCES/jackson-databind-2.9.9.2.tar.gz +SOURCES/jackson-databind-2.10.0.tar.gz diff --git a/.jackson-databind.metadata b/.jackson-databind.metadata index 4104f91..3085a9f 100644 --- a/.jackson-databind.metadata +++ b/.jackson-databind.metadata @@ -1 +1 @@ -ed198e8751601d96a06c88c62e346989b9396f99 SOURCES/jackson-databind-2.9.9.2.tar.gz +0d29a12dd73e668f9b00688a0ddbb932211be705 SOURCES/jackson-databind-2.10.0.tar.gz diff --git a/SPECS/jackson-databind.spec b/SPECS/jackson-databind.spec index 2aa3ff1..e751f2d 100644 --- a/SPECS/jackson-databind.spec +++ b/SPECS/jackson-databind.spec @@ -1,5 +1,5 @@ Name: jackson-databind -Version: 2.9.9.2 +Version: 2.10.0 Release: 1%{?dist} Summary: General data-binding package for Jackson (2.x) License: ASL 2.0 and LGPLv2+ @@ -7,12 +7,13 @@ URL: https://github.com/FasterXML/jackson-databind/ Source0: https://github.com/FasterXML/jackson-databind/archive/%{name}-%{version}.tar.gz BuildRequires: maven-local -BuildRequires: mvn(com.fasterxml.jackson.core:jackson-annotations) >= 2.9.9 -BuildRequires: mvn(com.fasterxml.jackson.core:jackson-core) >= 2.9.9 -BuildRequires: mvn(com.fasterxml.jackson:jackson-base:pom:) >= 2.9.9 + +# TODO: Revert back to version macro when versions align again. +BuildRequires: mvn(com.fasterxml.jackson.core:jackson-annotations) >= %{version} +BuildRequires: mvn(com.fasterxml.jackson.core:jackson-core) >= %{version} +BuildRequires: mvn(com.fasterxml.jackson:jackson-base:pom:) >= %{version} BuildRequires: mvn(com.google.code.maven-replacer-plugin:replacer) BuildRequires: mvn(org.apache.felix:maven-bundle-plugin) -BuildRequires: mvn(org.powermock:powermock-api-mockito) BuildRequires: mvn(org.powermock:powermock-module-junit4) BuildArch: noarch @@ -33,13 +34,15 @@ This package contains API documentation for %{name}. # Remove plugins unnecessary for RPM builds %pom_remove_plugin ":maven-enforcer-plugin" +%pom_remove_plugin "org.jacoco:jacoco-maven-plugin" +%pom_remove_plugin "org.moditect:moditect-maven-plugin" -cp -p src/main/resources/META-INF/LICENSE . cp -p src/main/resources/META-INF/NOTICE . sed -i 's/\r//' LICENSE NOTICE # unavailable test deps %pom_remove_dep javax.measure:jsr-275 +%pom_remove_dep org.powermock:powermock-api-mockito2 rm src/test/java/com/fasterxml/jackson/databind/introspect/NoClassDefFoundWorkaroundTest.java %pom_xpath_remove pom:classpathDependencyExcludes @@ -67,6 +70,13 @@ rm src/test/java/com/fasterxml/jackson/databind/ser/jdk/JDKTypeSerializationTest %license LICENSE NOTICE %changelog +* Fri Nov 8 2019 Red Hat PKI Team - 2.10.0-1 +- Update to latest upstream release +- Fixes: CVE-2019-14540 +- Fixes: CVE-2019-16335 +- Resolves: rhbz#1760274 +- Resolves: rhbz#1760278 + * Wed Jul 31 2019 Red Hat PKI Team - 2.9.9.2-1 - Update to latest upstream release, fixes CVE-2019-12384