Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

build(deps): bump logback from 1.2.11 to 1.2.13 (#7156) #7256

Merged
merged 1 commit into from
Dec 16, 2024

Conversation

nhumblot
Copy link
Collaborator

Description of Change

Upgrades logback version from 1.2.11 to 1.2.13 so Dependency Check stops flagging logback as being vulnerable to CVE-2023-6378. As it is just a patch update, this prevent requiring to upgrade slf4j at the same time and having to deal with breaking changes.

Related issues

Have test cases been added to cover the new functionality?

no

Copy link
Owner

@jeremylong jeremylong left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@jeremylong jeremylong merged commit 2328da1 into main Dec 16, 2024
9 checks passed
@jeremylong jeremylong added this to the 12.0.0 milestone Dec 16, 2024
@nhumblot nhumblot deleted the 7156-upgrade-logback branch December 16, 2024 19:55
marcelstoer pushed a commit to marcelstoer/DependencyCheck that referenced this pull request Dec 19, 2024
marcelstoer pushed a commit to marcelstoer/DependencyCheck that referenced this pull request Dec 19, 2024
marcelstoer pushed a commit to marcelstoer/DependencyCheck that referenced this pull request Dec 19, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants