Skip to content
This repository was archived by the owner on Dec 23, 2023. It is now read-only.

Update and weaken Log4J2 dependency#2085

Merged
punya merged 2 commits into
masterfrom
log4j2-mitigate
Dec 11, 2021
Merged

Update and weaken Log4J2 dependency#2085
punya merged 2 commits into
masterfrom
log4j2-mitigate

Conversation

@punya
Copy link
Copy Markdown
Contributor

@punya punya commented Dec 11, 2021

  • Use the more recent 2.15.0 as baseline
  • For the published package, express a provided dependency
    rather than actually pulling in Log4J2 ourselves

* Use the more recent 2.15.0 as baseline
* For the published package, express a provided dependency
  rather than actually pulling in Log4J2 ourselves
@punya punya requested review from a team, rghetia and songy23 as code owners December 11, 2021 20:26
@punya punya requested a review from jsuereth December 11, 2021 20:26
@punya punya merged commit 4852502 into master Dec 11, 2021
@punya punya deleted the log4j2-mitigate branch December 11, 2021 22:11
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants