Reading-eScience-Centre / edal-java

Environmental Data Abstraction Layer libraries
Other
39 stars 30 forks source link

Bump the log4j dependency version to v2.21.1 #160

Open sharon-tickell opened 1 year ago

sharon-tickell commented 1 year ago

The log4J dependencies in this library were to versions older than v2.17.0, which means that they still have the critical log4shell vulnerability. This PR updates both to v2.21.1, which is the current stable and supported version of log4j.