You are viewing a plain text version of this content. The canonical link for it is here.
Posted to reviews@kudu.apache.org by "Alexey Serbin (Code Review)" <ge...@cloudera.org> on 2021/12/20 19:55:36 UTC

[kudu-CR](branch-1.15.x) [java] bump log4j up to 2.17.0 version

Hello Attila Bukor, Kudu Jenkins,

I'd like you to do a code review. Please visit

    http://gerrit.cloudera.org:8080/18110

to review the following change.


Change subject: [java] bump log4j up to 2.17.0 version
......................................................................

[java] bump log4j up to 2.17.0 version

OK, log4j saga continues: 2.17.0 is the new shiny version to have once
the recent security vulnerability CVE-2021-44228 has been fixed
in 2.15.0.  Without going into the details, let's just update to the
most recent one to make various security scanners happy.

Release notes for the new version of the package is available at [1].

This is a follow-up to a6079a063c8f38166d91956ad46a4ce695a08019 and
ea67260aad998db7d34a94d25261e121a668faec.

[1] https://logging.apache.org/log4j/2.x/changes-report.html#a2.17.0

Change-Id: I8642063189ef7add4fc7b573008a4bfe7ac3d98b
Reviewed-on: http://gerrit.cloudera.org:8080/18109
Reviewed-by: Attila Bukor <ab...@apache.org>
Tested-by: Kudu Jenkins
(cherry picked from commit 84600f495e8cff24aa8794d7974d0b6fe77b95db)
---
M java/gradle/dependencies.gradle
1 file changed, 1 insertion(+), 1 deletion(-)



  git pull ssh://gerrit.cloudera.org:29418/kudu refs/changes/10/18110/1
-- 
To view, visit http://gerrit.cloudera.org:8080/18110
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: kudu
Gerrit-Branch: branch-1.15.x
Gerrit-MessageType: newchange
Gerrit-Change-Id: I8642063189ef7add4fc7b573008a4bfe7ac3d98b
Gerrit-Change-Number: 18110
Gerrit-PatchSet: 1
Gerrit-Owner: Alexey Serbin <as...@cloudera.com>
Gerrit-Reviewer: Attila Bukor <ab...@apache.org>
Gerrit-Reviewer: Kudu Jenkins (120)

[kudu-CR](branch-1.15.x) [java] bump log4j up to 2.17.0 version

Posted by "Alexey Serbin (Code Review)" <ge...@cloudera.org>.
Alexey Serbin has posted comments on this change. ( http://gerrit.cloudera.org:8080/18110 )

Change subject: [java] bump log4j up to 2.17.0 version
......................................................................


Patch Set 1: Code-Review+2


-- 
To view, visit http://gerrit.cloudera.org:8080/18110
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: kudu
Gerrit-Branch: branch-1.15.x
Gerrit-MessageType: comment
Gerrit-Change-Id: I8642063189ef7add4fc7b573008a4bfe7ac3d98b
Gerrit-Change-Number: 18110
Gerrit-PatchSet: 1
Gerrit-Owner: Alexey Serbin <as...@cloudera.com>
Gerrit-Reviewer: Alexey Serbin <as...@cloudera.com>
Gerrit-Reviewer: Attila Bukor <ab...@apache.org>
Gerrit-Reviewer: Kudu Jenkins (120)
Gerrit-Comment-Date: Mon, 20 Dec 2021 22:05:40 +0000
Gerrit-HasComments: No

[kudu-CR](branch-1.15.x) [java] bump log4j up to 2.17.0 version

Posted by "Alexey Serbin (Code Review)" <ge...@cloudera.org>.
Alexey Serbin has submitted this change and it was merged. ( http://gerrit.cloudera.org:8080/18110 )

Change subject: [java] bump log4j up to 2.17.0 version
......................................................................

[java] bump log4j up to 2.17.0 version

OK, log4j saga continues: 2.17.0 is the new shiny version to have once
the recent security vulnerability CVE-2021-44228 has been fixed
in 2.15.0.  Without going into the details, let's just update to the
most recent one to make various security scanners happy.

Release notes for the new version of the package is available at [1].

This is a follow-up to a6079a063c8f38166d91956ad46a4ce695a08019 and
ea67260aad998db7d34a94d25261e121a668faec.

[1] https://logging.apache.org/log4j/2.x/changes-report.html#a2.17.0

Change-Id: I8642063189ef7add4fc7b573008a4bfe7ac3d98b
Reviewed-on: http://gerrit.cloudera.org:8080/18109
Reviewed-by: Attila Bukor <ab...@apache.org>
Tested-by: Kudu Jenkins
(cherry picked from commit 84600f495e8cff24aa8794d7974d0b6fe77b95db)
Reviewed-on: http://gerrit.cloudera.org:8080/18110
Reviewed-by: Alexey Serbin <as...@cloudera.com>
---
M java/gradle/dependencies.gradle
1 file changed, 1 insertion(+), 1 deletion(-)

Approvals:
  Kudu Jenkins: Verified
  Alexey Serbin: Looks good to me, approved

-- 
To view, visit http://gerrit.cloudera.org:8080/18110
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: kudu
Gerrit-Branch: branch-1.15.x
Gerrit-MessageType: merged
Gerrit-Change-Id: I8642063189ef7add4fc7b573008a4bfe7ac3d98b
Gerrit-Change-Number: 18110
Gerrit-PatchSet: 2
Gerrit-Owner: Alexey Serbin <as...@cloudera.com>
Gerrit-Reviewer: Alexey Serbin <as...@cloudera.com>
Gerrit-Reviewer: Attila Bukor <ab...@apache.org>
Gerrit-Reviewer: Kudu Jenkins (120)