-
Notifications
You must be signed in to change notification settings - Fork 1.4k
fix(deps): upgrade slf4j and logback #8306
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
e999300
41373a9
a3dde1d
e7d7fe5
ffb3408
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Large diffs are not rendered by default.
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,69 @@ | ||
| /* | ||
| * This file is part of dependency-check-ant. | ||
| * | ||
| * Licensed under the Apache License, Version 2.0 (the "License"); | ||
| * you may not use this file except in compliance with the License. | ||
| * You may obtain a copy of the License at | ||
| * | ||
| * http://www.apache.org/licenses/LICENSE-2.0 | ||
| * | ||
| * Unless required by applicable law or agreed to in writing, software | ||
| * distributed under the License is distributed on an "AS IS" BASIS, | ||
| * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
| * See the License for the specific language governing permissions and | ||
| * limitations under the License. | ||
| * | ||
| * Copyright (c) 2015 The OWASP Foundation. All Rights Reserved. | ||
| */ | ||
| package org.owasp.dependencycheck.ant.logging; | ||
|
|
||
| import org.slf4j.ILoggerFactory; | ||
| import org.slf4j.IMarkerFactory; | ||
| import org.slf4j.helpers.BasicMarkerFactory; | ||
| import org.slf4j.helpers.NOPMDCAdapter; | ||
| import org.slf4j.spi.MDCAdapter; | ||
| import org.slf4j.spi.SLF4JServiceProvider; | ||
|
|
||
| /** | ||
| * SLF4J 2.0 service provider for the dependency-check Ant integration. | ||
| * Replaces the old StaticLoggerBinder mechanism used in SLF4J 1.x. | ||
| */ | ||
| public class AntSlf4jServiceProvider implements SLF4JServiceProvider { | ||
|
|
||
| /** | ||
| * Declare the version of the SLF4J API this implementation is compiled | ||
| * against. | ||
| */ | ||
| private static final String REQUESTED_API_VERSION = "2.0"; | ||
|
|
||
| private ILoggerFactory loggerFactory; | ||
| private IMarkerFactory markerFactory; | ||
| private MDCAdapter mdcAdapter; | ||
|
|
||
| @Override | ||
| public ILoggerFactory getLoggerFactory() { | ||
| return loggerFactory; | ||
| } | ||
|
|
||
| @Override | ||
| public IMarkerFactory getMarkerFactory() { | ||
| return markerFactory; | ||
| } | ||
|
|
||
| @Override | ||
| public MDCAdapter getMDCAdapter() { | ||
| return mdcAdapter; | ||
| } | ||
|
|
||
| @Override | ||
| public String getRequestedApiVersion() { | ||
| return REQUESTED_API_VERSION; | ||
| } | ||
|
|
||
| @Override | ||
| public void initialize() { | ||
| loggerFactory = new AntLoggerFactory(); | ||
| markerFactory = new BasicMarkerFactory(); | ||
| mdcAdapter = new NOPMDCAdapter(); | ||
| } | ||
| } | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,62 @@ | ||
| /* | ||
| * This file is part of dependency-check-ant. | ||
| * | ||
| * Licensed under the Apache License, Version 2.0 (the "License"); | ||
| * you may not use this file except in compliance with the License. | ||
| * You may obtain a copy of the License at | ||
| * | ||
| * http://www.apache.org/licenses/LICENSE-2.0 | ||
| * | ||
| * Unless required by applicable law or agreed to in writing, software | ||
| * distributed under the License is distributed on an "AS IS" BASIS, | ||
| * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
| * See the License for the specific language governing permissions and | ||
| * limitations under the License. | ||
| * | ||
| * Copyright (c) 2015 The OWASP Foundation. All Rights Reserved. | ||
| */ | ||
| package org.owasp.dependencycheck.ant.logging; | ||
|
|
||
| import org.apache.tools.ant.Task; | ||
|
|
||
| /** | ||
| * Holds a reference to the current Ant Task for logging. Replaces the old | ||
| * StaticLoggerBinder singleton pattern used with SLF4J 1.x. | ||
| * <p> | ||
| * Uses ThreadLocal to ensure thread-safety when Ant runs tasks in parallel. | ||
| * </p> | ||
| */ | ||
| public final class AntTaskHolder { | ||
|
|
||
| private static final ThreadLocal<Task> task = new ThreadLocal<>(); | ||
|
|
||
| private AntTaskHolder() { | ||
| } | ||
|
|
||
| /** | ||
| * Sets the current Ant task to use for logging. | ||
| * | ||
| * @param t the Ant task | ||
| */ | ||
| public static void setTask(Task t) { | ||
| task.set(t); | ||
| } | ||
|
|
||
| /** | ||
| * Returns the current Ant task. | ||
| * | ||
| * @return the Ant task, or null if not set | ||
| */ | ||
| public static Task getTask() { | ||
| return task.get(); | ||
| } | ||
|
|
||
| /** | ||
| * Removes the current Ant task from the thread-local storage. | ||
| * This should be called when the task completes to prevent memory leaks | ||
| * in environments with thread pooling. | ||
| */ | ||
| public static void remove() { | ||
| task.remove(); | ||
| } | ||
| } |
This file was deleted.
This file was deleted.
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1 @@ | ||
| org.owasp.dependencycheck.ant.logging.AntSlf4jServiceProvider | ||
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The SLF4J 2.x binding has been reworked to use a SLF4JServiceProvider, but there’s no test that asserts the provider is discoverable at runtime (e.g., that Ant execution doesn’t emit the “No SLF4J providers were found” warning and that expected log output is routed through the Ant task). Adding/adjusting an ant integration test to exercise the logging path would help catch packaging/service-loader regressions.