[SCA] Security upgrade @org.apache.logging.log4j:log4j-core from 2.7 to 2.25.4 #183
[SCA] Security upgrade @org.apache.logging.log4j:log4j-core from 2.7 to 2.25.4
#183
Conversation
Snyk has created this PR to upgrade org.apache.logging.log4j:log4j-core from 2.7 to 2.25.4. See this package in maven: org.apache.logging.log4j:log4j-core See this project in Snyk: https://app.snyk.io/org/gwunleong.lee/project/6d8f8930-2793-4d67-b2df-cc34344f7a1d?utm_source=github&utm_medium=referral&page=upgrade-pr
|
This is a significant upgrade from version 2.7 to 2.25.4, which introduces several breaking changes and requires a Java runtime update. Key Changes:
Recommendation: Given the mandatory Java version upgrade and multiple configuration changes, this upgrade carries a medium risk. Developers should:
Source: Apache Log4j Release Notes
|
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
This is a PR from Snyk, initiated by the Security team, to fix 9 vulnerabilities in the dependencies of this project.
Snyk changed the following file(s):
Important
#sca-supportSlack channel.References: