You are viewing a plain text version of this content. The canonical link for it is here.
Posted to reviews@kudu.apache.org by "Alexey Serbin (Code Review)" <ge...@cloudera.org> on 2021/12/20 19:20:05 UTC

[kudu-CR] [java] bump log4j up to 2.17.0 version

Alexey Serbin has uploaded this change for review. ( http://gerrit.cloudera.org:8080/18109


Change subject: [java] bump log4j up to 2.17.0 version
......................................................................

[java] bump log4j up to 2.17.0 version

OK, log4j saga continues: 2.17.0 is the new shiny version to have once
the recent security vulnerability CVE-2021-44228 has been fixed
in 2.15.0.  Without going into the details, let's just update to the
most recent one to make various security scanners happy.

Release notes for the new version of the package is available at [1].

This is a follow-up to a6079a063c8f38166d91956ad46a4ce695a08019 and
ea67260aad998db7d34a94d25261e121a668faec.

[1] https://logging.apache.org/log4j/2.x/changes-report.html#a2.17.0

Change-Id: I8642063189ef7add4fc7b573008a4bfe7ac3d98b
---
M java/gradle/dependencies.gradle
1 file changed, 1 insertion(+), 1 deletion(-)



  git pull ssh://gerrit.cloudera.org:29418/kudu refs/changes/09/18109/1
-- 
To view, visit http://gerrit.cloudera.org:8080/18109
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: kudu
Gerrit-Branch: master
Gerrit-MessageType: newchange
Gerrit-Change-Id: I8642063189ef7add4fc7b573008a4bfe7ac3d98b
Gerrit-Change-Number: 18109
Gerrit-PatchSet: 1
Gerrit-Owner: Alexey Serbin <as...@cloudera.com>

[kudu-CR] [java] bump log4j up to 2.17.0 version

Posted by "Attila Bukor (Code Review)" <ge...@cloudera.org>.
Attila Bukor has posted comments on this change. ( http://gerrit.cloudera.org:8080/18109 )

Change subject: [java] bump log4j up to 2.17.0 version
......................................................................


Patch Set 1: Code-Review+2


-- 
To view, visit http://gerrit.cloudera.org:8080/18109
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: kudu
Gerrit-Branch: master
Gerrit-MessageType: comment
Gerrit-Change-Id: I8642063189ef7add4fc7b573008a4bfe7ac3d98b
Gerrit-Change-Number: 18109
Gerrit-PatchSet: 1
Gerrit-Owner: Alexey Serbin <as...@cloudera.com>
Gerrit-Reviewer: Andrew Wong <aw...@cloudera.com>
Gerrit-Reviewer: Attila Bukor <ab...@apache.org>
Gerrit-Reviewer: Kudu Jenkins (120)
Gerrit-Comment-Date: Mon, 20 Dec 2021 19:21:10 +0000
Gerrit-HasComments: No

[kudu-CR] [java] bump log4j up to 2.17.0 version

Posted by "Alexey Serbin (Code Review)" <ge...@cloudera.org>.
Alexey Serbin has submitted this change and it was merged. ( http://gerrit.cloudera.org:8080/18109 )

Change subject: [java] bump log4j up to 2.17.0 version
......................................................................

[java] bump log4j up to 2.17.0 version

OK, log4j saga continues: 2.17.0 is the new shiny version to have once
the recent security vulnerability CVE-2021-44228 has been fixed
in 2.15.0.  Without going into the details, let's just update to the
most recent one to make various security scanners happy.

Release notes for the new version of the package is available at [1].

This is a follow-up to a6079a063c8f38166d91956ad46a4ce695a08019 and
ea67260aad998db7d34a94d25261e121a668faec.

[1] https://logging.apache.org/log4j/2.x/changes-report.html#a2.17.0

Change-Id: I8642063189ef7add4fc7b573008a4bfe7ac3d98b
Reviewed-on: http://gerrit.cloudera.org:8080/18109
Reviewed-by: Attila Bukor <ab...@apache.org>
Tested-by: Kudu Jenkins
---
M java/gradle/dependencies.gradle
1 file changed, 1 insertion(+), 1 deletion(-)

Approvals:
  Attila Bukor: Looks good to me, approved
  Kudu Jenkins: Verified

-- 
To view, visit http://gerrit.cloudera.org:8080/18109
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: kudu
Gerrit-Branch: master
Gerrit-MessageType: merged
Gerrit-Change-Id: I8642063189ef7add4fc7b573008a4bfe7ac3d98b
Gerrit-Change-Number: 18109
Gerrit-PatchSet: 2
Gerrit-Owner: Alexey Serbin <as...@cloudera.com>
Gerrit-Reviewer: Alexey Serbin <as...@cloudera.com>
Gerrit-Reviewer: Andrew Wong <aw...@cloudera.com>
Gerrit-Reviewer: Attila Bukor <ab...@apache.org>
Gerrit-Reviewer: Kudu Jenkins (120)