### _Why are the changes needed?_ Bumping log4j from 2.17.2 to 2.18.0 will reduce the risk of CVEs. ### _How was this patch tested?_ - [ ] Add some test cases that check the changes thoroughly including negative and positive cases if possible - [ ] Add screenshots for manual tests if appropriate - [x] [Run test](https://kyuubi.apache.org/docs/latest/develop_tools/testing.html#running-tests) locally before make a pull request (Ran ```./build/mvn clean test``` - see screenshots below for more info) Closes #3187 from ParisaTork/bump-log4j. Closes #3145 c9f9e4a8 [ParisaTork] Update dependency list c0d88f39 [ParisaTork] Bump log4j from 2.17.2 to 2.18.0 Authored-by: ParisaTork <47482049+ParisaTork@users.noreply.github.com> Signed-off-by: Cheng Pan <chengpan@apache.org> |
||
|---|---|---|
| .. | ||
| kyuubi-codecov | ||
| kyuubi-tpcds | ||
| checkout_pr.sh | ||
| dependencyList | ||
| merge_kyuubi_pr.py | ||
| reformat | ||