Jackson 3 upgrade in Data Center (Jira 12, Confluence 11, Bitbucket 11, Bamboo 13, Crowd 8)

New major releases of all Data Center products are in the works: Announcing upcoming major releases for Atlassian Data Center

We are upgrading from Jackson 2 to 3 in Jira 12, Confluence 11, Bitbucket 11, Bamboo 13, and Crowd 8.

This upgrade ensures we meet customers’ demands for secure, compliant products, keep dependencies within policy, and receive the latest updates. We must be proactive because our products and plugins rely heavily on Jackson, Jackson 2 has a history of vulnerabilities, while Jackson 3 has a more secure design. If your plugin uses only Jackson annotations, you likely don’t need to change anything. If your plugin depends on Jackson from the product system bundle, follow the official Jackson 3 migration guide. We also configured Jackson 3 in atlassian-rest to behave as closely as possible to Jackson 2.

Early access to Jackson 3 in Jira 11.3, Confluence 10.2, Bitbucket 10.2, Bamboo 12.1, and Crowd 7.2

We enabled Jackson 3 alongside Jackson 2 in Jira 11.3, Confluence 10.2, Bitbucket 10.2, Bamboo 12.1 and Crowd 7.2. In these product versions, both Jackson 2 and 3 are provided by the system bundle. Since REST endpoints use Jackson heavily, you can test Jackson 3 by adding use-jackson="3" to the REST module descriptor to run the endpoint with Jackson 3. For details, see the upgrade guide in atlassian-rest UPGRADE_9_1_0.md.

Jackson 3 upgrade in Jira 12, Confluence 11, Bitbucket 11, Bamboo 13 and Crowd 8

From the next major release, all DC products, Jira 12, Confluence 11, Bitbucket 11, Bamboo 13 and Crowd 8 will support only Jackson 3. Products will no longer include Jackson 2 in the system bundle, so plugins that use Jackson must migrate to Jackson 3. The use-jackson attribute in the REST module descriptor introduced in the early access will stop working; REST endpoints will use Jackson 3 internally.

1 Like