This releases provides a CycloneDX Software Bill of Materials (SBOM) along with each artifact and contains bug fixes addressing issues in the JPMS & OSGi infrastructure overhauled in 2.21.0, dependency updates, and some other minor fixes and improvements.
SBOM generation is streamlined by logging-parent, see its website for details.
Changed
Change the order of evaluation of FormattedMessage formatters. Messages are evaluated using java.util.Format only if they don't comply to the java.text.MessageFormat or ParameterizedMessage format. (#1223)
Change default encoding of HTTP Basic Authentication to UTF-8 and add log4j2.configurationAuthorizationEncoding property to overwrite it. (#1970)
Update com.fasterxml.jackson:jackson-bom to version 2.16.0 (#1974)
Update com.github.luben:zstd-jni to version 1.5.5-10 (#1940)
Update com.google.guava:guava to version 32.1.3-jre (#1875)
Update io.netty:netty-bom to version 4.1.101.Final (#1960)
Update org.eclipse.persistence:org.eclipse.persistence.jpa to version 2.7.13 (#1900)
Update org.fusesource.jansi:jansi to version 2.4.1 (#1907)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Bumps org.apache.logging.log4j:log4j-bom from 2.21.1 to 2.22.0.
Release notes
Sourced from org.apache.logging.log4j:log4j-bom's releases.
Commits
a1634d6
Release changelog for version2.22.0
4d27296
Update theproject.build.outputTimestamp
propertyd91092f
Fix.changelog.adoc.ftl
typo5c41c01
Improve release notesd6d9626
Update theproject.build.outputTimestamp
propertyb382a65
Remove explicitdistribution-attachment-*
arguments to CI9873b11
Update theproject.build.outputTimestamp
property38e133f
Release changelog200909c
Set the version to2.22.0
819b738
Merge remote-tracking branchppkarwasz/basic-auth
into2.x
(#1970)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show