apache / logging-log4j-kotlin

A Kotlin-friendly interface to log against the Log4j API
https://logging.apache.org/log4j/kotlin
Apache License 2.0
45 stars 11 forks source link

LOG4J2-3218 update log4j2 dep: CVE-2021-44228 #21

Closed rocketraman closed 2 years ago

rocketraman commented 2 years ago

@jvz I'll merge this to master shortly, but given the visibility of this issue, but FYI. We should probably cut a new release sooner rather than later.

rocketraman commented 2 years ago

Although given the vote in progress for 2.16.0, should we just skip 2.15.0 and go direct to 2.16.0 as soon as it is released?

garydgregory commented 2 years ago

Sure, it just won't hurt to update the file now, and then later again. I'll leave when to cut a release to the RM ;-)

jvz commented 2 years ago

Yeah, we can start a release later today.