Skip to content

Fix log4j Dependabot alerts - #12

Open
stasimus wants to merge 1 commit into
mainfrom
log4j-update
Open

stasimus wants to merge 1 commit into
mainfrom
log4j-update

Conversation

@stasimus

@stasimus stasimus commented Sep 6, 2026

Copy link
Copy Markdown
Contributor

log4j-core 2.11.2 comes in transitively from the sbt 1.4.5 dependency used for the sbt 1 cross-build leg. Raising the minimum sbt would drop users on older sbt, so instead log4j-api and log4j-core are pinned to 2.26.1 via dependencyOverrides. Runtime is unaffected since sbt itself provides log4j when the plugin runs.

@stasimus stasimus added the update Dependency update label Sep 6, 2026
@coderabbitai

coderabbitai Bot commented Sep 6, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Team

Run ID: bba5e9a6-97ab-4182-ac46-41c98b79680d


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

update Dependency update

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant