Hi Gary, On 22.11.2024 16:58, Gary Gregory wrote:
We have bumped the Log4j dependency and done some light housekeeping since Apache Commons Logging 1.3.4 was released, so I would like to release Apache Commons Logging 1.3.5.
Sorry, but I really don't see the point of this release. Log4j API is an **optional** release, so even if there were additional functionalities in 2.24.x that Commons Logging uses (and there aren't), users would not feel the change anyway.
The removal of an unmaintained Maven plugin (Cobertura) is a nice change, but it only affects our build environment. Since the change was committed to the Git repository, the security risk of using an unmaintained Maven plugin no longer exists.
Am I missing something? If so, could you expand the release notes? Piotr