Skip to content

Conversation

@psxjoy
Copy link
Member

@psxjoy psxjoy commented Mar 11, 2025

Ⅰ. Describe what this PR did

  • Upgraded log4j from version 2.18.0 to 2.24.3
  • Removed the unused dependency for logback
  • Updated slf4j to version 2.0.16
  • Removed the unused lombok dependency

Ⅱ. Does this pull request fix one issue?

fix #531

Ⅲ. Why don't you add test cases (unit test/integration test)?

Not applicable.

Ⅳ. Describe how to verify it

mvn clean install -DskipTests

Ⅴ. Special notes for reviews

This PR is a part of #558

@psxjoy psxjoy requested review from gaoxh, shanwb and wtt40122 and removed request for gaoxh and wtt40122 March 11, 2025 12:23
@psxjoy psxjoy requested a review from gaoxh March 12, 2025 06:59
Copy link
Contributor

@gaoxh gaoxh left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+LGTM

Copy link
Contributor

@wtt40122 wtt40122 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+LGTM

@wtt40122 wtt40122 merged commit 12c6cf6 into apache:master Mar 28, 2025
4 of 7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[SECURITY] upgrade log4j dependency

3 participants