Skip to content

Conversation

u-ways
Copy link
Contributor

@u-ways u-ways commented Jan 25, 2023

Hello,

It seems that the Log4j version is out of date.

Reason why to upgrade:

  • 2.17.0 is considered a vulnerable version by Gradle Portal.

Changes

  • Upgrade log4j to 2.19.0

Trivial changes - Feel free to amend as needed. :)

@u-ways
Copy link
Contributor Author

u-ways commented Jan 25, 2023

@jvz PR with only Log4j upgrade (Thanks for your time and being prompt)

@jvz jvz merged commit 8c781b7 into apache:master Jan 25, 2023
@jvz
Copy link
Member

jvz commented Jan 25, 2023

Thanks for the PR! Given the recent work being done to help streamline the release process for Log4j itself, I'd like to port that over to this repo, too, before the next release.

@jvz jvz added the dependencies Pull requests that update a dependency file label Jan 25, 2023
@jvz jvz self-assigned this Jan 25, 2023
@jvz jvz added this to the 1.2.1 milestone Jan 25, 2023
jvz added a commit that referenced this pull request Jan 28, 2023
@ppkarwasz ppkarwasz modified the milestones: 1.2.1, 1.3.0 Dec 27, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants