Skip to content

Vulnerability fixing version release plan if the 7.3 version has vulnerabilities #1025

Closed Answered by philsttr
07070529 asked this question in Q&A
Discussion options

You must be logged in to vote

If the vulnerability is in a dependency, such as jackson or logback, then no, since applications can upgrade those dependencies independently from logstash-logback-encoder.

If the vulnerability is reported directly against logstash-logback-encoder and can't be solved by upgrading a dependency, then I'll consider releasing a new version of 7.3 still supporting logback 1.2, but I make no promises.

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
0 replies
Answer selected by 07070529
Comment options

You must be logged in to vote
2 replies
@reneleonhardt
Comment options

@07070529
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants