# Is the dependent jars can be upgraded

**URL:** <https://discuss.elastic.co/t/is-the-dependent-jars-can-be-upgraded/268866>\
**Category:** Elasticsearch\
**Created:** [March 31, 2021, 5:53am UTC](https://discuss.elastic.co/t/is-the-dependent-jars-can-be-upgraded/268866 "2021-03-31T05:53:33Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mohammed\_rizwan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohammed_rizwan/32/67402_2.png) [@mohammed\_rizwan](https://discuss.elastic.co/u/mohammed_rizwan)\
**Post date:** [March 31, 2021, 5:53am UTC](https://discuss.elastic.co/t/is-the-dependent-jars-can-be-upgraded/268866/1 "2021-03-31T05:53:33Z")

</div>

Hi team,

We are using the elastic search 7.2.0 which depends on snakeyaml version 1.17.  
Snakeyaml 1.17 has security vulnerabilities and we plan to upgrade it to the latest version 1.28.

Is upgrading the dependant snakeyaml jars alone, recommended?  
Will elastic search works with snakeyaml 1.28 or do we have to stick with snakeyaml 1.17?

Thanks,  
Mohammed

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 31, 2021, 6:17am UTC](https://discuss.elastic.co/t/is-the-dependent-jars-can-be-upgraded/268866/2 "2021-03-31T06:17:51Z")

</div>

Welcome!

The recommendation is to upgrade Elasticsearch to 7.12.0 which is the latest.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 31, 2021, 7:32am UTC](https://discuss.elastic.co/t/is-the-dependent-jars-can-be-upgraded/268866/3 "2021-03-31T07:32:58Z")

</div>

> [@dadoonet](#):
>
> The recommendation is to upgrade Elasticsearch to 7.12.0 which is the latest.

And, to be clear, that is the only supported upgrade path to resolve issues like this.  
If you start upgrading individual JARs, you are running risks that we cannot help fix if things go wrong.

---

<div class="post-metadata">

**Author:** ![mohammed\_rizwan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohammed_rizwan/32/67402_2.png) [@mohammed\_rizwan](https://discuss.elastic.co/u/mohammed_rizwan)\
**Post date:** [April 1, 2021, 6:43am UTC](https://discuss.elastic.co/t/is-the-dependent-jars-can-be-upgraded/268866/4 "2021-04-01T06:43:54Z")

</div>

Thanks, @dadoonet, and @warkolm for the quick reply

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 29, 2021, 6:44am UTC](https://discuss.elastic.co/t/is-the-dependent-jars-can-be-upgraded/268866/5 "2021-04-29T06:44:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
