[ https://issues.apache.org/jira/browse/MJAVADOC-724?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17958103#comment-17958103 ]
Olivier Lamy commented on MJAVADOC-724: --------------------------------------- This project has moved from Jira to GitHub Issues. This issue was migrated to [apache/maven-javadoc-plugin#1094|https://github.com/apache/maven-javadoc-plugin/issues/1094]. > Maven Java Doc Plug-in v3.4.0 downloads Log4j-1.2.12 dependency transitively > ---------------------------------------------------------------------------- > > Key: MJAVADOC-724 > URL: https://issues.apache.org/jira/browse/MJAVADOC-724 > Project: Maven Javadoc Plugin (Moved to GitHub Issues) > Issue Type: Bug > Components: jar, javadoc > Environment: Windows 10 > Reporter: Yogesh Desai > Priority: Major > Labels: Vulnerability > > I have observed that Maven Java Doc Plug-in v3.4.0 downloads Log4j-1.2.12 > dependency transitively in .m2 folder. Since Log4j-1.X is strictly prohibited > for use in many organisations, we had no other option that not using the > plugin. Please plan to fix this issue and get rid of the log4j-1.X > dependency. Thanks! -- This message was sent by Atlassian Jira (v8.20.10#820010)