Skip to content
Discussion options

You must be logged in to vote

Since we do not include log4j, this is not an issue (note that the dependency is provided scope). Unfortunately these vulnerability scanners don't always understand the nature of a dependency. But, jboss-logging cannot be said to depend on log4j in any logical sense.

Replies: 3 comments 22 replies

Comment options

You must be logged in to vote
1 reply
@dmlloyd
Comment options

Comment options

You must be logged in to vote
0 replies
Answer selected by expertesantos
Comment options

You must be logged in to vote
21 replies
@expertesantos
Comment options

@dmlloyd
Comment options

@expertesantos
Comment options

@nicklasweasel
Comment options

@dmlloyd
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
6 participants