Skip to content
This repository has been archived by the owner on Dec 23, 2023. It is now read-only.

Update and weaken Log4J2 dependency #2085

Merged
merged 2 commits into from Dec 11, 2021
Merged

Update and weaken Log4J2 dependency #2085

merged 2 commits into from Dec 11, 2021

Conversation

punya
Copy link
Contributor

@punya punya commented Dec 11, 2021

  • Use the more recent 2.15.0 as baseline
  • For the published package, express a provided dependency
    rather than actually pulling in Log4J2 ourselves

* Use the more recent 2.15.0 as baseline
* For the published package, express a provided dependency
  rather than actually pulling in Log4J2 ourselves
@punya punya requested review from rghetia, songy23 and a team as code owners December 11, 2021 20:26
@punya punya requested a review from jsuereth December 11, 2021 20:26
@punya punya merged commit 4852502 into master Dec 11, 2021
@punya punya deleted the log4j2-mitigate branch December 11, 2021 22:11
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants