Uploaded image for project: 'Apache Ozone'
  1. Apache Ozone
  2. HDDS-6266

ozone public release 1.2.1 isn't using latest log4j

Attach filesAttach ScreenshotVotersWatch issueWatchersCreate sub-taskLinkCloneUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Major
    • Resolution: Duplicate
    • 1.2.1
    • None
    • build
    • None

    Description

      Hello,

      The release published here https://ozone.apache.org/release/1.2.1/ is still not using the latest log4j version:
      log4j-core-2.16.0.jar
      log4j-api-2.16.0.jar

       

      $ wget https://www.apache.org/dyn/closer.cgi/ozone/1.2.1/ozone-1.2.1.tar.gz
      $ tar -tvf ozone-1.2.1.tar.gz 'ozone-1.2.1/share/ozone/lib/log4j*'
      -rw-r--r-- ethanrose/staff 1789565 2021-12-15 17:40 ozone-1.2.1/share/ozone/lib/log4j-core-2.16.0.jar
      -rw-r--r-- ethanrose/staff  489884 2021-12-15 17:40 ozone-1.2.1/share/ozone/lib/log4j-1.2.17.jar
      -rw-r--r-- ethanrose/staff  301892 2021-12-15 17:40 ozone-1.2.1/share/ozone/lib/log4j-api-2.16.0.jar
      

       

      While each user can easily update their libraries, it would be good to have a release using log4j 2.17.1.

       

       

      Attachments

        Issue Links

        Activity

          This comment will be Viewable by All Users Viewable by All Users
          Cancel

          People

            Unassigned Unassigned
            djcelis Diego Jaramillo
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Slack

                Issue deployment