Skip to content

kotlin-analysis-intellij-1.6.21.jar is bundled with log4j 1.2 #2488

@Gamadril

Description

@Gamadril

Describe the bug
Seems that kotlin-analysis-intellij-1.6.21.jar is bundled with log4j version 1.2.17.2. NexusIQ is blocking it because of CVE-2022-23305. META-INF/maven/log4j/log4j/pom.xml confirms it.

Expected behaviour
Upgrade to log4j version without security issues.

To Reproduce
Check the dependency tree

Installation

  • Operating system: macOS
  • Build tool: Gradle v7.2
  • Dokka version: 1.6.21

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions