Skip to content

Conversation

@mlsorensen
Copy link

@mlsorensen mlsorensen commented Feb 4, 2022

Excludes log4j from transitive dependencies

mvn dependency:tree -Dincludes=log4j:log4j:jar | grep log4j comes back clean after this, have not tested functionality though.

@rohityadavcloud
Copy link
Member

Thanks Marcus, I'll merge the PR and we'll do a round of testing.

@rohityadavcloud rohityadavcloud merged commit cc027b5 into shapeblue:log4j-short-term-remedy Feb 4, 2022
rohityadavcloud added a commit that referenced this pull request Feb 8, 2022
* maven: migrate short-term to reload4j v1.2.18

This migrate to log4j 1.x fork, reload4j 1.2.18.0 which is drop-in
replacement and addresses some immediate CVE and issues.

* log4j migration to reload4j in pom xmls

Signed-off-by: Rohit Yadav <[email protected]>

* Exclude log4j from transitive dependencies (#73)

Co-authored-by: Marcus Sorensen <[email protected]>
Co-authored-by: Marcus Sorensen <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants