Skip to content

Bump apache-log4j from 2.26.0 to 2.26.1 - #4737

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/apache-log4j-2.26.1
Open

Bump apache-log4j from 2.26.0 to 2.26.1#4737
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/apache-log4j-2.26.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 13, 2026

Copy link
Copy Markdown

Bumps apache-log4j from 2.26.0 to 2.26.1.
Updates org.apache.logging.log4j:log4j-api from 2.26.0 to 2.26.1

Updates org.apache.logging.log4j:log4j-core from 2.26.0 to 2.26.1

Updates org.apache.logging.log4j:log4j-layout-template-json from 2.26.0 to 2.26.1

Updates org.apache.logging.log4j:log4j-slf4j2-impl from 2.26.0 to 2.26.1

Updates org.apache.logging.log4j:log4j-web from 2.26.0 to 2.26.1

Updates org.apache.logging.log4j:log4j-1.2-api from 2.26.0 to 2.26.1

@dependabot dependabot Bot added dependencies Dependency upgrades java Pull requests that update java code labels Aug 13, 2026
@epugh

epugh commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

@janhoy is this branch, main, not on the "clumping" routine of one big update per month?

@janhoy

janhoy commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

@janhoy is this branch, main, not on the "clumping" routine of one big update per month?

This is dependabot, not renovatebot. I think dependabot runs in a mode where it only bumps packages with known vulnerabilities in them, not any package with a newer version. So we could treat it as "more urgent" somehow? But I'd rather roll this feature into our solrbot - renovatebot has a feature where it can connect to dependency graph in github I think, but it is not setup.

@epugh

epugh commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

@janhoy is this branch, main, not on the "clumping" routine of one big update per month?

This is dependabot, not renovatebot. I think dependabot runs in a mode where it only bumps packages with known vulnerabilities in them, not any package with a newer version. So we could treat it as "more urgent" somehow? But I'd rather roll this feature into our solrbot - renovatebot has a feature where it can connect to dependency graph in github I think, but it is not setup.

Yeah, I don't see value in this, I see another source of noise that will be ignored. Do we have to ahve dependabot? I would love to not see these and just see the same monthly updates.

Bumps `apache-log4j` from 2.26.0 to 2.26.1.

Updates `org.apache.logging.log4j:log4j-api` from 2.26.0 to 2.26.1

Updates `org.apache.logging.log4j:log4j-core` from 2.26.0 to 2.26.1

Updates `org.apache.logging.log4j:log4j-layout-template-json` from 2.26.0 to 2.26.1

Updates `org.apache.logging.log4j:log4j-slf4j2-impl` from 2.26.0 to 2.26.1

Updates `org.apache.logging.log4j:log4j-web` from 2.26.0 to 2.26.1

Updates `org.apache.logging.log4j:log4j-1.2-api` from 2.26.0 to 2.26.1

---
updated-dependencies:
- dependency-name: org.apache.logging.log4j:log4j-1.2-api
  dependency-version: 2.26.1
  dependency-type: direct:production
- dependency-name: org.apache.logging.log4j:log4j-api
  dependency-version: 2.26.1
  dependency-type: direct:production
- dependency-name: org.apache.logging.log4j:log4j-core
  dependency-version: 2.26.1
  dependency-type: direct:production
- dependency-name: org.apache.logging.log4j:log4j-layout-template-json
  dependency-version: 2.26.1
  dependency-type: direct:production
- dependency-name: org.apache.logging.log4j:log4j-slf4j2-impl
  dependency-version: 2.26.1
  dependency-type: direct:production
- dependency-name: org.apache.logging.log4j:log4j-web
  dependency-version: 2.26.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/gradle/apache-log4j-2.26.1 branch from 3245442 to b173f6b Compare August 21, 2026 17:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency upgrades java Pull requests that update java code tool:build

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants