Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Exclude log4j from transitive dependencies#73

Merged
yadvr merged 1 commit intoshapeblue:log4j-short-term-remedyshapeblue/cloudstack:log4j-short-term-remedyfrom
mlsorensen:log4j-transitivemlsorensen/cloudstack:log4j-transitiveCopy head branch name to clipboard
Feb 4, 2022
Merged

Exclude log4j from transitive dependencies#73
yadvr merged 1 commit intoshapeblue:log4j-short-term-remedyshapeblue/cloudstack:log4j-short-term-remedyfrom
mlsorensen:log4j-transitivemlsorensen/cloudstack:log4j-transitiveCopy head branch name to clipboard

Conversation

@mlsorensen
Copy link

@mlsorensen mlsorensen commented Feb 4, 2022

Excludes log4j from transitive dependencies

mvn dependency:tree -Dincludes=log4j:log4j:jar | grep log4j comes back clean after this, have not tested functionality though.

@yadvr
Copy link
Member

yadvr commented Feb 4, 2022

Thanks Marcus, I'll merge the PR and we'll do a round of testing.

@yadvr yadvr closed this Feb 4, 2022
@yadvr yadvr reopened this Feb 4, 2022
@yadvr yadvr merged commit cc027b5 into shapeblue:log4j-short-term-remedy Feb 4, 2022
yadvr added a commit that referenced this pull request Feb 8, 2022
* maven: migrate short-term to reload4j v1.2.18

This migrate to log4j 1.x fork, reload4j 1.2.18.0 which is drop-in
replacement and addresses some immediate CVE and issues.

* log4j migration to reload4j in pom xmls

Signed-off-by: Rohit Yadav <rohit.yadav@shapeblue.com>

* Exclude log4j from transitive dependencies (#73)

Co-authored-by: Marcus Sorensen <shadowsor@gmail.com>
Co-authored-by: Marcus Sorensen <mls@apple.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

Morty Proxy This is a proxified and sanitized view of the page, visit original site.