Skip to content

Renew log4j 1.2.17 reference suppression to 2026-06-01#287

Merged
Jenson3210 merged 1 commit into
mainfrom
renew-log4j-suppression-2026-06
May 7, 2026
Merged

Renew log4j 1.2.17 reference suppression to 2026-06-01#287
Jenson3210 merged 1 commit into
mainfrom
renew-log4j-suppression-2026-06

Conversation

@Jenson3210
Copy link
Copy Markdown
Contributor

@Jenson3210 Jenson3210 commented May 7, 2026

Summary

The suppression for the log4j 1.2.17 reference jar expired on 2026-05-01. The jar is shipped only so the migration recipe can identify the legacy log4j artifact — it isn't loaded at runtime, so the CRITICAL CVEs against it remain non-exploitable in this context. Renewed until="2026-06-01Z".

Test plan

  • xmllint validates suppressions.xml
  • Next dependency-check scan no longer flags log4j 1.2.17 CVEs in this repo

Suppression expired 2026-05-01. Renewed; the log4j 1.2.17 jar is a
reference-only dependency used by the migration recipe to identify
the legacy log4j artifact, not loaded at runtime.

Refs moderneinc/dependency-vulnerability-reports#1054
@github-project-automation github-project-automation Bot moved this to In Progress in OpenRewrite May 7, 2026
@Jenson3210 Jenson3210 merged commit 43fc6c2 into main May 7, 2026
1 check passed
@Jenson3210 Jenson3210 deleted the renew-log4j-suppression-2026-06 branch May 7, 2026 14:49
@github-project-automation github-project-automation Bot moved this from In Progress to Done in OpenRewrite May 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

1 participant