Uploaded image for project: 'Beam'
  1. Beam
  2. BEAM-13481

Upgrade shadow plugin (log4j)

Details

    • Improvement
    • Status: Resolved
    • P2
    • Resolution: Fixed
    • None
    • 2.36.0
    • build-system
    • None

    Description

      Beam's current version of the shadow plugin (6.1.0) is dependent on a vulnerable version of log4j. The shadow plugin is run at compile time only, and is never bundled in any Beam applications, but the log4j dependency may still be problematic since some organizations may have blocked it.

      The shadow plugin has already made a new release, but it will require us to upgrade to Gradle 7 (BEAM-13430): https://github.com/johnrengelman/shadow/releases/tag/7.1.1

      Attachments

        Activity

          People

            dpcollins-google Daniel Collins
            ibzib Kyle Weaver
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: