Conversation
|
Hi @garydgregory, do we have a date to the next release? My team would love to upgrade our current version to the one that has this fix. Thanks. |
|
@pcoelho-coveo Why would you need this fix? HttpClient runtime does not depend on |
|
Yeah I am aware of that. We have an internal tool that scan our dependencies and it is currently flagging our http client dependency, even though the log4j is used only on the tests and is not included on our classpath. |
|
@pcoelho-coveo You should consider fixing the tool. |
Same shit from commercial scanners over and over again. A colleague of mine was requested to patch the following file: @ok2c If course we can fix that, the release manager receives a payment for the release from @pcoelho-coveo employer. |
You should use 2.17.1, it's been available for a while now. |
Version 2.17.0 fixes the issue CVE-2021-45105