This is an automated email from the ASF dual-hosted git repository.
FrankYang0529 pushed a commit to branch 4.2
in repository https://gitbox.apache.org/repos/asf/kafka.git
The following commit(s) were added to refs/heads/4.2 by this push:
new 063d69a85c0 KAFKA-20369 Upgrade log4j2 to 2.25.4 (#22117)
063d69a85c0 is described below
commit 063d69a85c0ac3eb62e1479103650197d802113c
Author: PoAn Yang <[email protected]>
AuthorDate: Thu Apr 23 08:38:59 2026 +0900
KAFKA-20369 Upgrade log4j2 to 2.25.4 (#22117)
cherry picked from commit 2759ea0dfade37f5ead2554dab4bd47572b5db18
Reviewers: Chia-Ping Tsai <[email protected]>, Federico Valeri
<[email protected]>, Ken Huang <[email protected]>
Co-authored-by: Murali Basani <[email protected]>
---
LICENSE-binary | 8 ++++----
gradle/dependencies.gradle | 2 +-
2 files changed, 5 insertions(+), 5 deletions(-)
diff --git a/LICENSE-binary b/LICENSE-binary
index fea9be22218..f9d598a93bc 100644
--- a/LICENSE-binary
+++ b/LICENSE-binary
@@ -237,10 +237,10 @@ License Version 2.0:
- jetty-util-12.0.34
- jose4j-0.9.6
- jspecify-1.0.0
-- log4j-api-2.25.3
-- log4j-core-2.25.3
-- log4j-slf4j-impl-2.25.3
-- log4j-1.2-api-2.25.3
+- log4j-api-2.25.4
+- log4j-core-2.25.4
+- log4j-slf4j-impl-2.25.4
+- log4j-1.2-api-2.25.4
- lz4-java-1.10.1
- maven-artifact-3.9.15
- metrics-core-2.2.0
diff --git a/gradle/dependencies.gradle b/gradle/dependencies.gradle
index ac548148b4e..de631167958 100644
--- a/gradle/dependencies.gradle
+++ b/gradle/dependencies.gradle
@@ -108,7 +108,7 @@ versions += [
kafka_40: "4.0.0",
kafka_41: "4.1.1",
kafka_42: "4.2.0",
- log4j2: "2.25.3",
+ log4j2: "2.25.4",
// When updating lz4 make sure the compression levels in
org.apache.kafka.common.record.CompressionType are still valid
//
https://github.com/apache/kafka/blob/trunk/clients/src/main/java/org/apache/kafka/common/record/CompressionType.java#L73-L74
//
https://github.com/yawkat/lz4-java/blob/main/src/java/net/jpountz/lz4/LZ4Constants.java#L23-L24