Skip to content

Vulnerability in quarkus-core dependency #43607

Closed Answered by dmlloyd
expertesantos asked this question in Q&A
Discussion options

You must be logged in to vote

Since we do not include log4j, this is not an issue (note that the dependency is provided scope). Unfortunately these vulnerability scanners don't always understand the nature of a dependency. But, jboss-logging cannot be said to depend on log4j in any logical sense.

Replies: 3 comments 22 replies

Comment options

You must be logged in to vote
1 reply
@dmlloyd
Comment options

Comment options

You must be logged in to vote
0 replies
Answer selected by expertesantos
Comment options

You must be logged in to vote
21 replies
@expertesantos
Comment options

@dmlloyd
Comment options

@expertesantos
Comment options

@nicklasweasel
Comment options

@dmlloyd
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
6 participants