I've seen that we already upgraded to log4j 2.16.0. I will start preparing the releases, starting with 3.7.7.
Thanks, Gregor On Mon, Dec 13, 2021 at 2:56 PM Andrea Cosentino <anco...@gmail.com> wrote: > > Sounds good for me. > > +1. > > Il giorno lun 13 dic 2021 alle ore 14:53 Claus Ibsen <claus.ib...@gmail.com> > ha scritto: > > > Hi > > > > Camel 3.7.x is reaching its EOL by end of this month. > > > > With the log4j incident, then it could benefit us if we do fresh > > releases of the LTS branches. > > > > The 3.7.x branch has been upgraded to log4j 2.15.0 and there is one > > last thing I will backport related to exclude log4j-core in two camel > > components, that the 3rd party library pulls in. > > https://issues.apache.org/jira/browse/CAMEL-17324 > > > > If we do this then all our LTS releases are upgraded to the latest > > log4j and there is absolutely no problem at all. > > > > > > > > -- > > Claus Ibsen > > ----------------- > > http://davsclaus.com @davsclaus > > Camel in Action 2: https://www.manning.com/ibsen2 > >