Uploaded image for project: 'Kylin'
  1. Kylin
  2. KYLIN-5174

remove log4jv1 dependency

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Open
    • Major
    • Resolution: Unresolved
    • None
    • None
    • None
    • None

    Description

      Log4j v1 is end of life and has multiple unfixed security issues.

      Replacements include:

      • log4j v2 (eg v2.17.1)
      • logback
      • reload4j (a drop in replacement for log4j v1)

      This is an example line in kylin build:

      https://github.com/apache/kylin/blob/main/pom.xml#L144

      Attachments

        Activity

          People

            Unassigned Unassigned
            pj.fanning PJ Fanning
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated: