I thought I fixed it until I did "gradlew dependencies" so I naturally did
more fixes 'till gradlew dependencies gave me more optimistic results.
credits:
https://stackoverflow.com/questions/70317385/gradle-java-how-to-upgrade-log4j-safely
https://blog.gradle.org/log4j-vulnerability