This is an automated email from the ASF dual-hosted git repository.
rainyu pushed a commit to branch 3.3
in repository https://gitbox.apache.org/repos/asf/dubbo.git
The following commit(s) were added to refs/heads/3.3 by this push:
new d95086ca29 build(deps): bump org.apache.logging.log4j:log4j-core
(#16204)
d95086ca29 is described below
commit d95086ca29bce4b41a8181f17ae67e42afc9ed02
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
AuthorDate: Mon Apr 13 11:36:15 2026 +0800
build(deps): bump org.apache.logging.log4j:log4j-core (#16204)
Bumps org.apache.logging.log4j:log4j-core from 2.25.3 to 2.25.4.
---
updated-dependencies:
- dependency-name: org.apache.logging.log4j:log4j-core
dependency-version: 2.25.4
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot]
<49699333+dependabot[bot]@users.noreply.github.com>
---
dubbo-dependencies-bom/pom.xml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/dubbo-dependencies-bom/pom.xml b/dubbo-dependencies-bom/pom.xml
index bf0ba7d2ba..22ece239e1 100644
--- a/dubbo-dependencies-bom/pom.xml
+++ b/dubbo-dependencies-bom/pom.xml
@@ -151,7 +151,7 @@
<log4j_version>1.2.17</log4j_version>
<logback_version>1.2.13</logback_version>
<!-- Fix the bug of log4j
refer:https://github.com/apache/logging-log4j2/pull/608 -->
- <log4j2_version>2.25.3</log4j2_version>
+ <log4j2_version>2.25.4</log4j2_version>
<commons_io_version>2.21.0</commons_io_version>
<commons-codec_version>1.21.0</commons-codec_version>
<groovy_version>4.0.30</groovy_version>