From ff8dc42cce557b940a3546a47a10a0c0c1a34006 Mon Sep 17 00:00:00 2001 From: Nikita Pande <37657012+nikita15p@users.noreply.github.com> Date: Tue, 13 Aug 2024 19:46:52 +0530 Subject: [PATCH] HBASE-28532 Remove vulnerable dependencies: slf4j-log4j12 and log4j:log4j (#142) Signed-off-by: Duo Zhang Signed-off-by: Nihal Jain Reviewed-by: Peng Lu --- hbase-hbck2/pom.xml | 24 ++++++++++++++++++++++++ hbase-table-reporter/pom.xml | 14 ++++++++++---- hbase-tools/pom.xml | 24 ++++++++++++++++++++++++ pom.xml | 3 ++- 4 files changed, 60 insertions(+), 5 deletions(-) diff --git a/hbase-hbck2/pom.xml b/hbase-hbck2/pom.xml index 3876daddcd..1d572253fe 100644 --- a/hbase-hbck2/pom.xml +++ b/hbase-hbck2/pom.xml @@ -68,6 +68,12 @@ hbase-server ${hbase.version} provided + + + log4j + log4j + + org.apache.hbase @@ -75,6 +81,12 @@ ${hbase.version} test-jar provided + + + log4j + log4j + + org.apache.hbase @@ -82,6 +94,12 @@ ${hbase.version} test-jar provided + + + log4j + log4j + + org.apache.hbase @@ -89,6 +107,12 @@ ${hbase.version} test-jar provided + + + log4j + log4j + + org.apache.hbase diff --git a/hbase-table-reporter/pom.xml b/hbase-table-reporter/pom.xml index 1cedca723b..64cdfd1e1e 100644 --- a/hbase-table-reporter/pom.xml +++ b/hbase-table-reporter/pom.xml @@ -42,17 +42,23 @@ org.slf4j slf4j-api - 1.7.25 + ${slf4j.version} - org.slf4j - slf4j-log4j12 - 1.7.25 + org.apache.logging.log4j + log4j-slf4j-impl + ${log4j2.version} org.apache.hbase hbase-shaded-client ${hbase.version} + + + log4j + log4j + + org.apache.datasketches diff --git a/hbase-tools/pom.xml b/hbase-tools/pom.xml index 7a803605a9..55ef075bd6 100644 --- a/hbase-tools/pom.xml +++ b/hbase-tools/pom.xml @@ -58,12 +58,24 @@ hbase-server ${hbase.version} provided + + + log4j + log4j + + org.apache.hbase hbase-shaded-testing-util ${hbase.version} test + + + log4j + log4j + + org.apache.hbase @@ -71,6 +83,12 @@ ${hbase.version} test-jar provided + + + log4j + log4j + + org.apache.hbase @@ -78,6 +96,12 @@ ${hbase.version} test-jar provided + + + log4j + log4j + + org.apache.hbase diff --git a/pom.xml b/pom.xml index 3e05590ee5..3ec62435b0 100644 --- a/pom.xml +++ b/pom.xml @@ -129,7 +129,8 @@ 2.27.2 2.4.4 2.2.1 - 2.17.1 + 2.17.2 + 1.7.33 surefire-junit47 true 8.45.1