From ed082ade1ec460a0310b78d71e84906862ff269c Mon Sep 17 00:00:00 2001 From: Sandesh <30489233+j-sandy@users.noreply.github.com> Date: Thu, 10 Aug 2023 21:01:29 +0530 Subject: [PATCH] chore(dependency): upgrade and pin logback to 1.2.12 (#1086) Pinning logback to 1.2.12 till spring boot upgrade to 2.5.15 or above --- spinnaker-dependencies/spinnaker-dependencies.gradle | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/spinnaker-dependencies/spinnaker-dependencies.gradle b/spinnaker-dependencies/spinnaker-dependencies.gradle index d3dfece34..ab8fe695b 100644 --- a/spinnaker-dependencies/spinnaker-dependencies.gradle +++ b/spinnaker-dependencies/spinnaker-dependencies.gradle @@ -17,9 +17,9 @@ ext { jsch : "0.1.54", jschAgentProxy : "0.0.9", // spring boot 2.5.14 specifies logback 1.2.11, but a rosco test hung with - // 1.2.11 from https://jira.qos.ch/browse/LOGBACK-1623 so stick with 1.2.10 - // until 1.2.12 appears. - logback : "1.2.10", + // 1.2.11 from https://jira.qos.ch/browse/LOGBACK-1623 so pinning it to 1.2.12 + // until spring boot upgrade 2.5.15 or above. + logback : "1.2.12", protobuf : "3.21.12", okhttp : "2.7.5", // CVE-2016-2402 okhttp3 : "4.9.3", @@ -91,7 +91,7 @@ dependencies { constraints { api("cglib:cglib-nodep:3.3.0") //A bug is reported in 1.2.11 and fixed in 1.2.12. - //So pinning the version to 1.2.10 untill required package is released. + //So pinning the version to 1.2.12 untill spring boot upgrade to 2.5.15 or above. //[https://jira.qos.ch/browse/LOGBACK-1623] api("ch.qos.logback:logback-core"){ version {