Skip to content

Conversation

@nhumblot
Copy link
Collaborator

Description of Change

Upgrades logback version from 1.2.11 to 1.2.13 so Dependency Check stops flagging logback as being vulnerable to CVE-2023-6378. As it is just a patch update, this prevent requiring to upgrade slf4j at the same time and having to deal with breaking changes.

Related issues

Have test cases been added to cover the new functionality?

no

Copy link
Collaborator

@jeremylong jeremylong left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@jeremylong jeremylong merged commit 2328da1 into main Dec 16, 2024
9 checks passed
@jeremylong jeremylong added this to the 12.0.0 milestone Dec 16, 2024
@nhumblot nhumblot deleted the 7156-upgrade-logback branch December 16, 2024 19:55
marcelstoer pushed a commit to marcelstoer/DependencyCheck that referenced this pull request Dec 19, 2024
marcelstoer pushed a commit to marcelstoer/DependencyCheck that referenced this pull request Dec 19, 2024
marcelstoer pushed a commit to marcelstoer/DependencyCheck that referenced this pull request Dec 19, 2024
@github-actions github-actions bot locked as resolved and limited conversation to collaborators Jan 16, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants