Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Comments

Close side panel

Update log4j-core and log4j-api dependencies to 2.15.0#285

Merged
carlzogh merged 1 commit intoaws:masteraws/aws-lambda-java-libs:masterfrom
carlzogh:mastercarlzogh/aws-lambda-java-libs:masterCopy head branch name to clipboard
Dec 10, 2021
Merged

Update log4j-core and log4j-api dependencies to 2.15.0#285
carlzogh merged 1 commit intoaws:masteraws/aws-lambda-java-libs:masterfrom
carlzogh:mastercarlzogh/aws-lambda-java-libs:masterCopy head branch name to clipboard

Conversation

@carlzogh
Copy link
Contributor

Description of changes:

  • Update log4j-core and log4j-api dependencies to 2.15.0
  • Stage update to aws-lambda-java-log4j2 version 1.3.0

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

Copy link
Contributor

@msailes msailes left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@carlzogh carlzogh merged commit af945fa into aws:master Dec 10, 2021
@berry120
Copy link

@msailes Will new versions of these libraries be published to maven shortly with the updated log4j2 deps? (Don't wish to push, just trying to work out the best way of handling this internally given the 0 day!)

@carlzogh
Copy link
Contributor Author

@berry120 the publish to Maven is happening right now, thanks for insisting on the highest standards!

@sndl
Copy link

sndl commented Dec 10, 2021

@carlzogh looks like it wasn't published, 1.3.0 is still missing in maven. This step is marked as failed on the commit: "AWS CodeBuild eu-west-1 (CodeCommitSync-aws-lambda-java-libs)"

@berry120
Copy link

@msailes Without wishing this to become a common thing (!) is it worth now making a similar PR for log4j 2.16.0? No known 0 day as of yet with 2.15.0 of course, but 2.16.0 goes a step further with security that should help to prevent similar, as of yet unknown exploits. If so then happy to create the PR.

@msailes
Copy link
Contributor

msailes commented Dec 14, 2021

@berry120 Thanks for the comment, I'll pass this onto the team.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

Morty Proxy This is a proxified and sanitized view of the page, visit original site.