[ https://issues.apache.org/jira/browse/TINKERPOP-2948?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17743044#comment-17743044 ]
ASF GitHub Bot commented on TINKERPOP-2948: ------------------------------------------- codecov-commenter commented on PR #2139: URL: https://github.com/apache/tinkerpop/pull/2139#issuecomment-1635488816 ## [Codecov](https://app.codecov.io/gh/apache/tinkerpop/pull/2139?src=pr&el=h1&utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=apache) Report > Merging [#2139](https://app.codecov.io/gh/apache/tinkerpop/pull/2139?src=pr&el=desc&utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=apache) (d12f9eb) into [3.5-dev](https://app.codecov.io/gh/apache/tinkerpop/commit/1eb6fc249432c8946c6542a41df45c449b5f0819?el=desc&utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=apache) (1eb6fc2) will **increase** coverage by `0.07%`. > The diff coverage is `n/a`. ```diff @@ Coverage Diff @@ ## 3.5-dev #2139 +/- ## ============================================= + Coverage 69.85% 69.93% +0.07% ============================================= Files 865 24 -841 Lines 40975 3449 -37526 Branches 5455 0 -5455 ============================================= - Hits 28625 2412 -26213 + Misses 10443 860 -9583 + Partials 1907 177 -1730 ``` [see 841 files with indirect coverage changes](https://app.codecov.io/gh/apache/tinkerpop/pull/2139/indirect-changes?src=pr&el=tree-more&utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=apache) :mega: We’re building smart automated test selection to slash your CI/CD build times. [Learn more](https://about.codecov.io/iterative-testing/?utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=apache) > PRISMA security vulnerabilty for jackson-databind 2.14.0 > -------------------------------------------------------- > > Key: TINKERPOP-2948 > URL: https://issues.apache.org/jira/browse/TINKERPOP-2948 > Project: TinkerPop > Issue Type: Bug > Components: server > Affects Versions: 3.6.3, 3.5.6 > Reporter: Aaron Coady > Priority: Critical > > > h1. PRISMA-2023-0067 logged against jackson-databind 2.14.0 > [https://github.com/FasterXML/jackson-core/pull/827] > > com.fasterxml.jackson.core_jackson-core package versions before 2.15.0 are > vulnerable to Denial of Service (DoS). The package does not properly restrict > the size or amount of resources that are requested or influenced by an actor, > which can be used to consume more resources than intended and leads to > Uncontrolled Resource Consumption ('Resource Exhaustion') -- This message was sent by Atlassian Jira (v8.20.10#820010)