JinwooHwang opened a new pull request, #7982: URL: https://github.com/apache/geode/pull/7982
### Problem Logback is pulled in as a transitive dependency from `spring-boot-starter-logging:3.3.5`, exposing the project to multiple CVEs: - CVE-2024-12798 - CVE-2024-12801 - CVE-2025-11226 - CVE-2026-1225 Logback is not used anywhere in the codebase - all logging is routed through Log4j 2 via `log4j-slf4j-impl`. ### Solution Added global exclusion of `ch.qos.logback` group in `build.gradle` configurations to prevent transitive inclusion. Updated all expected POM files to reflect the dependency changes. ### Testing - All unit tests passing (235 tasks) - Build validation - Verified logback completely removed from runtime classpath - Confirmed no logback imports in codebase ### Changes - Modified `build.gradle`: Added global logback exclusion with documentation - Updated 26 `expected-pom.xml` files across modules to reflect dependency changes <!-- Thank you for submitting a contribution to Apache Geode. --> <!-- In order to streamline review of your contribution we ask that you ensure you've taken the following steps. --> ### For all changes, please confirm: - [x] Is there a JIRA ticket associated with this PR? Is it referenced in the commit message? - [x] Has your PR been rebased against the latest commit within the target branch (typically `develop`)? - [x] Is your initial contribution a single, squashed commit? - [x] Does `gradlew build` run cleanly? - [ ] Have you written or updated unit tests to verify your changes? - [ ] If adding new dependencies to the code, are these dependencies licensed in a way that is compatible for inclusion under [ASF 2.0](http://www.apache.org/legal/resolved.html#category-a)? -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
