-
Bug
-
Resolution: Done
-
Major
-
2.2.5.ER2, 2.2.5.ER3
Looking at 2.2.5.Final-redhat-00004, there is still log4j-api 2.17.0 managed http://indy.psi.redhat.com/api/content/maven/remote/group-static/io/quarkus/quarkus-bom/2.2.5.Final-redhat-00004/quarkus-bom-2.2.5.Final-redhat-00004.pom
janstey@redhat.com mentioned that prodsec requires 2.17.1 even if it is -api that did not have any CVEs
We (Camel Quarkus) wanted to rely on quarkus-bom managing log4j-api 2.17.1 to fulfill the prodsec requirements, but like this we even cannot override the version in our BOM. I assume in the platform, the quarkus version would win anyway.
- is blocked by
-
QUARKUS-1731 Missing log4j-api dependency in maven repo zip
- Closed