Skip to content

Conversation

diegov
Copy link
Contributor

@diegov diegov commented Dec 14, 2021

Description of the change

Update log4j dependencies to v 2.16.0

This version provides additional protection against CVE-2021-44228:

Type of change

  • Bug fix (non-breaking change that fixes an issue)
  • New feature (non-breaking change that adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Maintenance
  • New release

Related issues

Checklists

Development

  • Lint rules pass locally
  • The code changed/added as part of this pull request has been covered with tests
  • All tests related to the changed code pass in development

Code review

  • This pull request has a descriptive title and information useful to a reviewer. There may be a screenshot or screencast attached
  • "Ready for review" label attached to the PR and reviewers assigned
  • Issue from task tracker has a link to this pull request
  • Changes have been reviewed by at least one other engineer

@diegov diegov requested review from bxsx and bishopb December 14, 2021 16:21
@diegov diegov marked this pull request as ready for review December 14, 2021 16:34
Copy link

@bishopb bishopb left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@diegov diegov merged commit ab647b2 into master Dec 14, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Fix log4j2 vulnerability
2 participants