Become a sponsor to QOS.CH (Switzerland)
Sponsor the logging stack Java already runs on
If you ship software on the JVM, you almost certainly depend on this work. SLF4J and logback are downloaded over 4 billion times a year. Frameworks pick them as defaults; applications inherit them. They sit on the request path of a large share of production Java.
When logging fails, it fails everywhere. Log4Shell made that plain. Logback has long been the usual implementation, (about 50% of logging implementations among Java projects on Maven Central, and we are not aware of any attacks reported against it. That is the outcome we work for: a framework that is reliable first, then fast and flexible.
This is a twenty-five-year stewardship, not a side project. In 2000, QOS.CH (Switzerland) donated log4j to the Apache Software Foundation and maintained log4j 1.x until 2006. We founded the Apache Logging top-level project and served as its first PMC chair. In 2006 we started SLF4J and logback, and we still maintain them. In 2022, with log4j 1.x at end of life and still widely deployed, we started reload4j to patch its critical security issues.
Reliability at this scale is slow, careful work: reviewing reports, fixing vulnerabilities, keeping old applications compatible, answering users. Sponsorship is what buys time for that work.
We thank the organisations and individuals who already sponsor us. If SLF4J or logback runs in your systems, we would be glad to have you with them.
Meet the team
-
Ceki Gülcü cekiFounder of log4j 1.x, slf4j and logback projects. Currently working on slf4j, logback and reload4j. Unaffiliated with log4j 2.x.