Skip to content

fix(deps): update dependency org.apache.logging.log4j:log4j-core to v2.25.3 - #1049

Open
mend-for-github-com[bot] wants to merge 1 commit into
mainfrom
whitesource-remediate/log4jversion
Open

fix(deps): update dependency org.apache.logging.log4j:log4j-core to v2.25.3#1049
mend-for-github-com[bot] wants to merge 1 commit into
mainfrom
whitesource-remediate/log4jversion

Conversation

@mend-for-github-com

@mend-for-github-com mend-for-github-com Bot commented May 27, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
org.apache.logging.log4j:log4j-core (source) 2.24.12.25.3 age adoption passing confidence

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS Score Vulnerability
Medium Medium 4.0 CVE-2025-68161

  • If you want to rebase/retry this PR, check this box

…2.25.3

Signed-off-by: mend-for-github-com[bot] <mend-for-github-com[bot]@users.noreply.github.com>
@mend-for-github-com mend-for-github-com Bot added the security fix Security fix generated by Mend label May 27, 2026
@mend-for-github-com mend-for-github-com Bot changed the title fix(deps): update dependency org.apache.logging.log4j:log4j-core to v2.25.3 fix(deps): update log4jversion Jun 29, 2026
@mend-for-github-com mend-for-github-com Bot changed the title fix(deps): update log4jversion fix(deps): update dependency org.apache.logging.log4j:log4j-core to v2.25.3 Jul 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

distinguished-contributor security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants