Daniel Chen  created SAMZA-2683:
-----------------------------------

             Summary: Bump up Scalatra version to pull latest dependencies
                 Key: SAMZA-2683
                 URL: https://issues.apache.org/jira/browse/SAMZA-2683
             Project: Samza
          Issue Type: Improvement
    Affects Versions: 1.6
            Reporter: Daniel Chen 
            Assignee: Daniel Chen 
             Fix For: 1.7


Scalatra 2.5.0 is pulling in outdated libraries, namely log4j:1.2.14 which 
possesses security concerns

The latest Scalatra 2.7.1 version no longer depends on this dangerous library



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Reply via email to