oblac / jodd

Jodd! Lightweight. Java. Zero dependencies. Use what you like.
https://jodd.org
BSD 2-Clause "Simplified" License
4.06k stars 723 forks source link

Upgrade log4j to 2.15.0 - CVE-2021-44228 #785

Closed rhowe closed 2 years ago

rhowe commented 2 years ago

PR Checklist

Please check if your PR fulfills the following requirements:

Not completely sure whether I got the dependency spec correct - ./gradlew dependencies didn't show log4j so I'm not really sure what's going on but hopefully this is a helpful nudge if nothing else.

igr commented 2 years ago

Yeah, it is not a dependency, but still OK :)

rhowe commented 2 years ago

Yeah, it is not a dependency, but still OK :)

Interesting - the Debian package of this library lists it as a dependency