On Thu, Oct 8, 2020 at 11:00 AM Tamas Penzes <[email protected]> wrote:
> Hi All, > > I would open a discussion about log4j2 update. > Would we consider going up to log4j2 in a minor release (e.g. 3.7) or only > in a major one, like 4.0? > The latest log4j1 version (1.2.17) is really old and vulnerable, but log4j2 > has a different config format, which means users should adopt their config > files when updating ZooKeeper. > Afaik we are compatible with both of them because of slf4j, but the default > is log4j1 at the moment. > > What do you think about going up to log4j2 with 3.7? > > Tamaas there's lots of background on this jira: https://issues.apache.org/jira/browse/ZOOKEEPER-2342 In particular concern with b/w compat. There is also a patch attached. Is there a way we can provide run time selection without impacting code in a non-bw compatible way? Have other projects been able to solve this? Patrick > Thanks, Tamaas >
