Skip to content

build(deps): bump logback from 1.2.11 to 1.2.13 (#7156)#7256

Merged
jeremylong merged 1 commit intomainfrom
7156-upgrade-logback
Dec 16, 2024
Merged

build(deps): bump logback from 1.2.11 to 1.2.13 (#7156)#7256
jeremylong merged 1 commit intomainfrom
7156-upgrade-logback

Conversation

@nhumblot
Copy link
Copy Markdown
Collaborator

Description of Change

Upgrades logback version from 1.2.11 to 1.2.13 so Dependency Check stops flagging logback as being vulnerable to CVE-2023-6378. As it is just a patch update, this prevent requiring to upgrade slf4j at the same time and having to deal with breaking changes.

Related issues

Have test cases been added to cover the new functionality?

no

Copy link
Copy Markdown
Collaborator

@jeremylong jeremylong left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@jeremylong jeremylong merged commit 2328da1 into main Dec 16, 2024
@jeremylong jeremylong added this to the 12.0.0 milestone Dec 16, 2024
@nhumblot nhumblot deleted the 7156-upgrade-logback branch December 16, 2024 19:55
marcelstoer pushed a commit to marcelstoer/DependencyCheck that referenced this pull request Dec 19, 2024
marcelstoer pushed a commit to marcelstoer/DependencyCheck that referenced this pull request Dec 19, 2024
marcelstoer pushed a commit to marcelstoer/DependencyCheck that referenced this pull request Dec 19, 2024
@github-actions github-actions bot locked as resolved and limited conversation to collaborators Jan 16, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants