Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependencies #44

Open
vruano opened this issue Oct 23, 2024 · 0 comments
Open

Update dependencies #44

vruano opened this issue Oct 23, 2024 · 0 comments

Comments

@vruano
Copy link

vruano commented Oct 23, 2024

Any plans to update dependencies to remedy security issues.

These are a potential show stoppers for adopting this utility in my organization and I hate
to have to do that

Perhaps the best known is the one involving log4j 2 and log4j-1 specially the former.
log4j-1 should be avoided and log4j 2 should not be earlier than 2.17.1 I think (please don't take my word for that, check it out and report) and the current dependency is 2.14.x. These are not direct dependencies but rather pulled in thru third party libraries, so that makes it. a bit challenging

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant