From fdf6c85fd2ed72f19640ea00f80c2bf295cf0a52 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 26 Sep 2022 11:13:31 +0000 Subject: [PATCH] Bump org.apache.logging.log4j dependency set from 2.17.1 to 2.19.0 Bumps `org.apache.logging.log4j` dependency set from 2.17.1 to 2.19.0. Updates `log4j-api` from 2.17.1 to 2.19.0 Updates `log4j-to-slf4j` from 2.17.1 to 2.19.0 --- updated-dependencies: - dependency-name: org.apache.logging.log4j:log4j-api dependency-type: direct:production update-type: version-update:semver-minor - dependency-name: org.apache.logging.log4j:log4j-to-slf4j dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] --- build.gradle | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/build.gradle b/build.gradle index 32946d1ac8..36dcd2173c 100644 --- a/build.gradle +++ b/build.gradle @@ -161,7 +161,7 @@ allprojects { entry 'tomcat-embed-el' } //CVE-2021-44228, CVE-2021-44832, CVE-2021-45046, CVE-2021-45105 - dependencySet(group: 'org.apache.logging.log4j', version: '2.17.1') { + dependencySet(group: 'org.apache.logging.log4j', version: '2.19.0') { entry 'log4j-api' entry 'log4j-to-slf4j' }