You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@phoenix.apache.org by "Istvan Toth (Jira)" <ji...@apache.org> on 2022/01/31 11:49:00 UTC
[jira] [Updated] (PHOENIX-6636) Replace bundled log4j libraries with reload4j
[ https://issues.apache.org/jira/browse/PHOENIX-6636?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Istvan Toth updated PHOENIX-6636:
---------------------------------
Description:
To reduce the number of dependecies with unresolved CVEs, replace the bundled log4j libraries with reload4j ([https://reload4j.qos.ch/).]
This will also require bumping the slf4j version.
This is a quick fix, and does not preclude moving to some different backend later (like log4j2 or logback)
was:
To reduce the number of dependecies with unresolved CVEs, replace the bundled slf4j libraries with reload4j ([https://reload4j.qos.ch/).]
This will also require bumping the slf4j version.
This is a quick fix, and does not preclude moving to some different backend later (like log4j2 or logback)
Summary: Replace bundled log4j libraries with reload4j (was: Replace bundled slf4j libraries with reload4j)
> Replace bundled log4j libraries with reload4j
> ---------------------------------------------
>
> Key: PHOENIX-6636
> URL: https://issues.apache.org/jira/browse/PHOENIX-6636
> Project: Phoenix
> Issue Type: Bug
> Components: connectors, core, queryserver
> Affects Versions: 5.2.0
> Reporter: Istvan Toth
> Priority: Major
>
> To reduce the number of dependecies with unresolved CVEs, replace the bundled log4j libraries with reload4j ([https://reload4j.qos.ch/).]
> This will also require bumping the slf4j version.
> This is a quick fix, and does not preclude moving to some different backend later (like log4j2 or logback)
--
This message was sent by Atlassian Jira
(v8.20.1#820001)