Merge branch '2.8' into 2.9
diff --git a/release-notes/VERSION-2.x b/release-notes/VERSION-2.x
index 61c3430..2425368 100644
--- a/release-notes/VERSION-2.x
+++ b/release-notes/VERSION-2.x
@@ -8,6 +8,7 @@
 #1854: NPE deserializing collection with `@JsonCreator` and `ACCEPT_CASE_INSENSITIVE_PROPERTIES`
  (reported by rue-jw@github)
 #1855: More blacklisting of serialization gadgets
+#1855: Blacklist for more serialization gadgets (dbcp/tomcat, spring)
 
 2.9.3 (09-Dec-2017)