Expected Behaviour
Use of the latest version of powertools does not raise a Dependabot security vulnerability
Current Behaviour
Use of the latest version of powertools results in the following Dependabot security notification related to the transitive jackson-core dependency, with High severity:
Code snippet
Possible Solution
Apologies, I wasn't sure which template to use here but hopefully the bug template is most appropriate.
There is a Dependabot PR on your repository that would fix the issue here, though CI is currently failing: #2403
Steps to Reproduce
- Use the latest version of a relevant Powertools library in a project with Dependabot security alerts enabled
- Observe the security alert raised against the project
Powertools for AWS Lambda (Java) version
2.9.0
AWS Lambda function runtime
Java 17
Debugging logs
Expected Behaviour
Use of the latest version of powertools does not raise a Dependabot security vulnerability
Current Behaviour
Use of the latest version of powertools results in the following Dependabot security notification related to the transitive jackson-core dependency, with High severity:
Code snippet
Possible Solution
Apologies, I wasn't sure which template to use here but hopefully the bug template is most appropriate.
There is a Dependabot PR on your repository that would fix the issue here, though CI is currently failing: #2403
Steps to Reproduce
Powertools for AWS Lambda (Java) version
2.9.0
AWS Lambda function runtime
Java 17
Debugging logs