Closed jonathonherbert closed 2 years ago
co-authored-with: @andrew-nowak
Bumps log4j to a safe version. It's pulled in transitively by aws-lambda-java-log4j2:1.1.0.
aws-lambda-java-log4j2:1.1.0
Also adds the dependencyTree plugin, which gives us an easy way of querying for dependencies for this versoin of sbt.
dependencyTree
sbt
Run sbt dependencyTree | grep log4j. You should see that any log4j dependencies are > 2.15.x.
sbt dependencyTree | grep log4j
2.15.x
co-authored-with: @andrew-nowak
What does this change?
Bumps log4j to a safe version. It's pulled in transitively by
aws-lambda-java-log4j2:1.1.0
.Also adds the
dependencyTree
plugin, which gives us an easy way of querying for dependencies for this versoin ofsbt
.How to test
Run
sbt dependencyTree | grep log4j
. You should see that any log4j dependencies are >2.15.x
.