[SCA] Security upgrade @org.apache.logging.log4j:log4j-core from 2.7 to 2.25.4 #172
[SCA] Security upgrade @org.apache.logging.log4j:log4j-core from 2.7 to 2.25.4
#172gwnlng wants to merge 2 commits into
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769 - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804
|
This is a significant upgrade from version 2.7 to 2.25.4, which introduces several breaking changes and requires a Java runtime update. Key Changes:
Recommendation: Given the mandatory Java version upgrade and multiple configuration changes, this upgrade carries a medium risk. Developers should:
Source: Apache Log4j Release Notes
|
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967769 - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHELOGGINGLOG4J-15967804
This is a PR from Snyk, initiated by the Security team, to fix 2 vulnerabilities in the dependencies of this project.
Snyk changed the following file(s):
Important
#sca-supportSlack channel.References: