-
Hi, Thanks. |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 2 replies
-
If the vulnerability is in a dependency, such as jackson or logback, then no, since applications can upgrade those dependencies independently from logstash-logback-encoder. If the vulnerability is reported directly against logstash-logback-encoder and can't be solved by upgrading a dependency, then I'll consider releasing a new version of 7.3 still supporting logback 1.2, but I make no promises. |
Beta Was this translation helpful? Give feedback.
-
Thanks for your reply, we understand. |
Beta Was this translation helpful? Give feedback.
If the vulnerability is in a dependency, such as jackson or logback, then no, since applications can upgrade those dependencies independently from logstash-logback-encoder.
If the vulnerability is reported directly against logstash-logback-encoder and can't be solved by upgrading a dependency, then I'll consider releasing a new version of 7.3 still supporting logback 1.2, but I make no promises.