Skip to content

Conversation

@sharon-tickell
Copy link

The log4J dependencies in this library were to versions older than v2.17.0, which means that they still have the critical log4shell vulnerability. This PR updates both to v2.21.1, which is the current stable and supported version of log4j.

@sharon-tickell sharon-tickell changed the title Bump the log4j dependency version to v2.21.1 Bump the log4j dependency version to latest stable version (> 2.17.0) Mar 4, 2025
@sharon-tickell
Copy link
Author

Another version bump: the latest stable log4j version is 2.24.3 as per https://logging.apache.org/log4j/2.x/download.html

sharon-tickell added a commit to onaci/edal-java that referenced this pull request Mar 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant