You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@datafu.apache.org by "Arpit Bhardwaj (Jira)" <ji...@apache.org> on 2022/10/05 09:44:00 UTC

[jira] [Comment Edited] (DATAFU-162) Upgrade Log4j version

    [ https://issues.apache.org/jira/browse/DATAFU-162?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17612929#comment-17612929 ] 

Arpit Bhardwaj edited comment on DATAFU-162 at 10/5/22 9:43 AM:
----------------------------------------------------------------

[~immu2able] Are you still on it?

Let me know if i can pick it up.


was (Author: JIRAUSER296428):
[~immu2able] Are you still on it. Let me know if i can pick it up.

> Upgrade Log4j version
> ---------------------
>
>                 Key: DATAFU-162
>                 URL: https://issues.apache.org/jira/browse/DATAFU-162
>             Project: DataFu
>          Issue Type: Improvement
>            Reporter: Eyal Allweil
>            Priority: Major
>              Labels: up-for-grabs
>
> Although the [infamous Log4J vulnerability|https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44832] is not relevant for DataFu (we are dependent on log4j 1.x, which is not affected) it is still a pretty good idea to upgrade to a new version.
> The upgrade should keep our logs as similar as possible to the existing version, but this shouldn't necessitate a major version release since this isn't a breaking change.
>  
> We can start by fixing this for datafu-spark (we don't need to update the other projects since they might be deprecated soon)



--
This message was sent by Atlassian Jira
(v8.20.10#820010)