Skip to content

log4j #138

@spyhunter99

Description

@spyhunter99

Hi i was attempting to publish a library that uses this library as a dependency. oss.sonatype.org send me a "lift" report that flagged this library as having a few security related issues. It looks like it's related to log4j 1.x.

Seeing this in the root pom

yes we know this is an issue but it is here for backwards compatibility

As a user of the library, can we exclude the log4j dependency and have the library still be functional?
Alternatively, is there a plan to use some other logging library or a newer version?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions