Skip to content

Commit ec5e8f7

Browse files
authored
Update slf4j and logback versions (deephaven#5102)
Fixes CVE-2023-6378, related to logback receiver component vulnerabilities. While our default deployment is not vulnerable, it's theoretically possible a custom logback configuration would be vulnerable.
1 parent ce6b33e commit ec5e8f7

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

buildSrc/src/main/groovy/Classpaths.groovy

+2-2
Original file line numberDiff line numberDiff line change
@@ -49,7 +49,7 @@ class Classpaths {
4949
static final String ARROW_VERSION = '13.0.0'
5050

5151
static final String SLF4J_GROUP = 'org.slf4j'
52-
static final String SLF4J_VERSION = '2.0.6'
52+
static final String SLF4J_VERSION = '2.0.11'
5353

5454
static final String FLATBUFFER_GROUP = 'com.google.flatbuffers'
5555
static final String FLATBUFFER_NAME = 'flatbuffers-java'
@@ -88,7 +88,7 @@ class Classpaths {
8888

8989
static final String LOGBACK_GROUP = 'ch.qos.logback'
9090
static final String LOGBACK_NAME = 'logback-classic'
91-
static final String LOGBACK_VERSION = '1.4.5'
91+
static final String LOGBACK_VERSION = '1.4.14'
9292

9393
static final String GROOVY_GROUP = 'org.codehaus.groovy'
9494
static final String GROOVY_VERSION = '3.0.18'

0 commit comments

Comments
 (0)