Re: Compile `release-2.x` with JDK 11

2022-06-12 Thread Andrew Marlow
n this will give log4j2 a longer lease of life which will be very important for people who have moved there from log4j-v1 and don't want to go near log4j3 for a long time yet. Also I am sure many projects will be on jdk-8 for quite some time yet. -- Regards, Andrew Marlow http://www.andrewpetermarlow.co.uk

Re: [logging-log4j1] branch v1.2.8 created (now 0cde9dd)

2022-01-07 Thread Andrew Marlow
my comment is below: On Fri, 7 Jan 2022 at 14:23, Christian Grobmeier wrote: > Hello, > > On Fri, Jan 7, 2022, at 08:21, Ceki Gülcü wrote: > > As for infringing on the log4j trademark, I will rename the repo to > > something else, for example "re4j". > > > > As mentioned in my previous message,

Re: [DISCUSS] The future of Log4j 1.x

2021-12-25 Thread Andrew Marlow
> > If you have other proposals feel free to state them. > > This discussion will be followed up by a vote thread if necessary. > > Ralph > > > -- Regards, Andrew Marlow http://www.andrewpetermarlow.co.uk

Re: Resurrecting log4j 1.x

2021-12-24 Thread Andrew Marlow
On Thu, 23 Dec 2021 at 15:13, Volkan Yazıcı wrote: > Vladimir, mind helping us to quantify this "need", please? To the best of > my knowledge, nobody has reached out to us with such a request except you > and Leo. That's not quite right. A while ago I asked if the RedHat fix could be added to l

Re: Log4J 1.x progress, pull request(s), plans

2021-12-18 Thread Andrew Marlow
https://github.com/apache/commons-parent/blob/master/pom.xml > > > > Leads to question: how do we feel about removal of .lf5 (javax.swing > > logging) and .chainsaw (java.awt logging) packages? > > > > It's an old change that was already on the trunk. > > > > > > > > > https://github.com/apache/log4j/pull/16/commits/5c29c4048b4860aa7f6a86420f20208459e6c22c#diff-9c5fb3d1b7e3b0f54bc5c4182965c4fe1f9023d449017cece3005d3f90e8e4d8R251 > > > > I can understand why it was made. > > > > > > Cheers, > > > > > > Leo > > > -- Regards, Andrew Marlow http://www.andrewpetermarlow.co.uk

Re: Test framework updates (was: vote thread)

2020-11-09 Thread Andrew Marlow
then some other items). > I’ve been adapting our test tooling to use the JUnit 5 extension API which > is fairly different from the v4 API, and I don’t think I’ve even ported > over all the functionality of LoggerContextRule yet. > -- Regards, Andrew Marlow http://www.andrewpetermarlow.co.uk

Re: [CVE-2018-1285] XXE vulnerability in Apache log4net

2020-05-25 Thread Andrew Marlow
re > frameworks? > > Please let me know. > > Regards > Suthish > -- Regards, Andrew Marlow http://www.andrewpetermarlow.co.uk

Re: Modularization

2020-03-08 Thread Andrew Marlow
internal” off of core. > Rather than having internal directories all over the place I am thinking we > should mimic the same existing package structure under the internal > directory and move private classes there. > > Thoughts? > > Ralph > -- Regards, Andrew Marlow http://www.andrewpetermarlow.co.uk

Re: Blog post

2019-12-17 Thread Andrew Marlow
me/why-was-log4j-2-created. I plan to write > a few entries on what is new in Log4J. > > Ralph -- Regards, Andrew Marlow http://www.andrewpetermarlow.co.uk

Re: Is there any chance that there will be a security fix for log4j-v1.2.17?

2019-12-15 Thread Andrew Marlow
to perform a release. >> > Log4j 1.x supported an ancient version of the JDK (1.2?). I am not even >> > sure if that is possible any more. The oldest version I have installed >> is >> > 1.7. I would have no idea how to validate that it was still compatible. >>

Re: Is there any chance that there will be a security fix for log4j-v1.2.17?

2019-12-15 Thread Andrew Marlow
e that it was still compatible. > > > > Ralph > > > > > On Dec 15, 2019, at 7:25 AM, Gary Gregory > > wrote: > > > > > > Security issues should not be discussed in public for obvious reasons. > > > Please see https://www.apache.org/security/ &g

Re: Is there any chance that there will be a security fix for log4j-v1.2.17?

2019-12-15 Thread Andrew Marlow
; On Dec 15, 2019, at 7:25 AM, Gary Gregory > wrote: > > > > Security issues should not be discussed in public for obvious reasons. > > Please see https://www.apache.org/security/ > > > > Gary > > > > > > On Sun, Dec 15, 2019 at 7:01 AM Andrew Marlow >

Is there any chance that there will be a security fix for log4j-v1.2.17?

2019-12-15 Thread Andrew Marlow
? -- Regards, Andrew Marlow http://www.andrewpetermarlow.co.uk