[ 
https://issues.apache.org/jira/browse/PHOENIX-6636?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17498108#comment-17498108
 ] 

ASF GitHub Bot commented on PHOENIX-6636:
-----------------------------------------

stoty closed pull request #1379:
URL: https://github.com/apache/phoenix/pull/1379


   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


> Replace bundled log4j libraries with reload4j
> ---------------------------------------------
>
>                 Key: PHOENIX-6636
>                 URL: https://issues.apache.org/jira/browse/PHOENIX-6636
>             Project: Phoenix
>          Issue Type: Bug
>          Components: connectors, core, queryserver
>    Affects Versions: 5.2.0
>            Reporter: Istvan Toth
>            Assignee: Istvan Toth
>            Priority: Major
>             Fix For: 4.17.0, 5.2.0, 4.16.2, 5.1.3
>
>
> To reduce the number of dependecies with unresolved CVEs, replace the bundled 
> log4j libraries with reload4j ([https://reload4j.qos.ch/).]
> This will also require bumping the slf4j version.
> This is a quick fix, and does not preclude moving to some different backend 
> later (like log4j2 or logback)



--
This message was sent by Atlassian Jira
(v8.20.1#820001)

Reply via email to