Skip to content

Vulnerability in quarkus-core dependency #43607

Closed Answered by dmlloyd
expertesantos asked this question in Q&A
Discussion options

You must be logged in to vote

Since we do not include log4j, this is not an issue (note that the dependency is provided scope). Unfortunately these vulnerability scanners don't always understand the nature of a dependency. But, jboss-logging cannot be said to depend on log4j in any logical sense.

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
1 reply
@dmlloyd
Comment options

Comment options

You must be logged in to vote
0 replies
Answer selected by expertesantos
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants