Skip to content
This repository has been archived by the owner on Dec 13, 2023. It is now read-only.

Force log4j dep version to avoid 0-day exploit #2636

Merged
merged 1 commit into from
Dec 10, 2021

Conversation

marcocrasso
Copy link
Contributor

Pull Request type

  • [ X] Other (please describe):

Security. Log4j discovered vulnerability:

Changes in this PR

Forces to upgrade transitive dependencies versions to use patched ones.

@marcocrasso
Copy link
Contributor Author

@aravindanr
I suggest to merge this PR for security reasons. This change-set fixes "log4shell" issue that was discovered today. To test this, hit ./gradlew dependencies and check:

image

@aravindanr aravindanr added the type: important Important changes label Dec 10, 2021
@aravindanr aravindanr merged commit 19e8d0f into Netflix:main Dec 10, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
type: important Important changes
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants