Skip to content

Blanket exclude log4j.
 - #3453

Closed
metasim wants to merge 1 commit into
locationtech:masterfrom
metasim:fix/3451
Closed

metasim wants to merge 1 commit into
locationtech:masterfrom
metasim:fix/3451

Conversation

@metasim

@metasim metasim commented Mar 24, 2022

Copy link
Copy Markdown
Member

Closes #3451

@metasim
metasim requested a review from pomadchin March 24, 2022 19:41

@pomadchin pomadchin left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! But I'm not sure that this change will be reflected in the published packages pom files.

Comment thread project/Settings.scala
}
},

excludeDependencies += "log4j" % "log4j",

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@metasim thx for the PR!

As far as I know, excludeDependencieswould not be reflected in the published artifacts (i.e. see https://repo1.maven.org/maven2/org/locationtech/geotrellis/geotrellis-geotools_2.12/3.6.1/geotrellis-geotools_2.12-3.6.1.pom), could you double check the behavior / switch to using ExclusionRules instead?

@pomadchin

pomadchin commented Mar 25, 2022 •

Copy link
Copy Markdown
Member

@metasim I think I found a way to go the other direction. GT is a library, so I just moved that log4j bridge into the test scope so it won't affect users.

See 7e067c0

Will be resolved in terms of #3452

@pomadchin pomadchin mentioned this pull request Mar 25, 2022
12 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Exclude log4j 1.x dependency

2 participants