Skip to content

Conversation

@bereng
Copy link
Collaborator

@bereng bereng commented Jan 20, 2026

Update logback to 1.5.25 to address:

What is the issue

Some libraries need updating to address CVEs

What does this PR fix and why was it fixed

The library was updated to the latest version to address said CVEs

Update logback to 1.5.25 to address:
 * NVD - CVE-2024-12798
 * NVD - CVE-2024-12798
 * NVD - CVE-2025-11226
@github-actions
Copy link

github-actions bot commented Jan 20, 2026

Checklist before you submit for review

  • This PR adheres to the Definition of Done
  • Make sure there is a PR in the CNDB project updating the Converged Cassandra version
  • Use NoSpamLogger for log lines that may appear frequently in the logs
  • Verify test results on Butler
  • Test coverage for new/modified code is > 80%
  • Proper code formatting
  • Proper title for each commit staring with the project-issue number, like CNDB-1234
  • Each commit has a meaningful description
  • Each commit is not very long and contains related changes
  • Renames, moves and reformatting are in distinct commits
  • All new files should contain the DataStax copyright header instead of the Apache License one

@bereng
Copy link
Collaborator Author

bereng commented Jan 20, 2026

CI LGTM

  • 2 unrelated timeouts
  • That failure passes locally: [junit-timeout] Testsuite: org.apache.cassandra.index.sai.cql.GenericOrderByTest-.jdk11 Tests run: 8, Failures: 0, Errors: 0, Skipped: 0, Time elapsed: 9.125 sec

@bereng
Copy link
Collaborator Author

bereng commented Jan 23, 2026

DO NOT MERGE INTO CC MAIN.

This will get merged or cherrypicked into a CC branch specific to the HCD-1.2.5 release.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants