Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view

Large diffs are not rendered by default.

Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,6 @@
*/
package org.owasp.dependencycheck.ant.logging;

import org.apache.tools.ant.Task;
import org.slf4j.ILoggerFactory;
import org.slf4j.Logger;

Expand All @@ -28,29 +27,14 @@
*/
public class AntLoggerFactory implements ILoggerFactory {

/**
* A reference to the Ant logger Adapter.
*/
private final AntLoggerAdapter antLoggerAdapter;

/**
* Constructs a new Ant Logger Factory.
*
* @param task the Ant task to use for logging
*/
public AntLoggerFactory(Task task) {
super();
this.antLoggerAdapter = new AntLoggerAdapter(task);
}

/**
* Returns the Ant logger adapter.
*
* @param name ignored in this implementation
* @param name the logger name
* @return the Ant logger adapter
*/
@Override
public Logger getLogger(String name) {
return antLoggerAdapter;
return new AntLoggerAdapter(name);
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,69 @@
/*
* This file is part of dependency-check-ant.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*
* Copyright (c) 2015 The OWASP Foundation. All Rights Reserved.
*/
package org.owasp.dependencycheck.ant.logging;

import org.slf4j.ILoggerFactory;
import org.slf4j.IMarkerFactory;
import org.slf4j.helpers.BasicMarkerFactory;
import org.slf4j.helpers.NOPMDCAdapter;
import org.slf4j.spi.MDCAdapter;
import org.slf4j.spi.SLF4JServiceProvider;

/**
* SLF4J 2.0 service provider for the dependency-check Ant integration.
* Replaces the old StaticLoggerBinder mechanism used in SLF4J 1.x.
*/
public class AntSlf4jServiceProvider implements SLF4JServiceProvider {

/**
* Declare the version of the SLF4J API this implementation is compiled
* against.
*/
private static final String REQUESTED_API_VERSION = "2.0";

private ILoggerFactory loggerFactory;
private IMarkerFactory markerFactory;
private MDCAdapter mdcAdapter;

@Override
public ILoggerFactory getLoggerFactory() {
return loggerFactory;
}

@Override
public IMarkerFactory getMarkerFactory() {
return markerFactory;
}

@Override
public MDCAdapter getMDCAdapter() {
return mdcAdapter;
}

@Override
public String getRequestedApiVersion() {
return REQUESTED_API_VERSION;
}

@Override
public void initialize() {
loggerFactory = new AntLoggerFactory();
markerFactory = new BasicMarkerFactory();
mdcAdapter = new NOPMDCAdapter();
}
Comment on lines +63 to +68
Copy link

Copilot AI Feb 15, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The SLF4J 2.x binding has been reworked to use a SLF4JServiceProvider, but there’s no test that asserts the provider is discoverable at runtime (e.g., that Ant execution doesn’t emit the “No SLF4J providers were found” warning and that expected log output is routed through the Ant task). Adding/adjusting an ant integration test to exercise the logging path would help catch packaging/service-loader regressions.

Copilot uses AI. Check for mistakes.
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,62 @@
/*
* This file is part of dependency-check-ant.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*
* Copyright (c) 2015 The OWASP Foundation. All Rights Reserved.
*/
package org.owasp.dependencycheck.ant.logging;

import org.apache.tools.ant.Task;

/**
* Holds a reference to the current Ant Task for logging. Replaces the old
* StaticLoggerBinder singleton pattern used with SLF4J 1.x.
* <p>
* Uses ThreadLocal to ensure thread-safety when Ant runs tasks in parallel.
* </p>
*/
public final class AntTaskHolder {

private static final ThreadLocal<Task> task = new ThreadLocal<>();

private AntTaskHolder() {
}

/**
* Sets the current Ant task to use for logging.
*
* @param t the Ant task
*/
public static void setTask(Task t) {
task.set(t);
}

/**
* Returns the current Ant task.
*
* @return the Ant task, or null if not set
*/
public static Task getTask() {
return task.get();
}

/**
* Removes the current Ant task from the thread-local storage.
* This should be called when the task completes to prevent memory leaks
* in environments with thread pooling.
*/
public static void remove() {
task.remove();
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@
import org.owasp.dependencycheck.utils.Settings;
import org.owasp.dependencycheck.utils.SeverityUtil;
import org.owasp.dependencycheck.utils.scarf.TelemetryCollector;
import org.slf4j.impl.StaticLoggerBinder;
import org.owasp.dependencycheck.ant.logging.AntTaskHolder;

//CSOFF: MethodCount
/**
Expand Down Expand Up @@ -517,7 +517,7 @@ public Check() {
super();
// Call this before Dependency Check Core starts logging anything - this way, all SLF4J messages from
// core end up coming through this tasks logger
StaticLoggerBinder.getSingleton().setTask(this);
AntTaskHolder.setTask(this);
}

/**
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@
import org.owasp.dependencycheck.utils.Downloader;
import org.owasp.dependencycheck.utils.InvalidSettingException;
import org.owasp.dependencycheck.utils.Settings;
import org.slf4j.impl.StaticLoggerBinder;
import org.owasp.dependencycheck.ant.logging.AntTaskHolder;

/**
* An Ant task definition to execute dependency-check during an Ant build.
Expand Down Expand Up @@ -65,7 +65,7 @@ public Purge() {

// Call this before Dependency Check Core starts logging anything - this way, all SLF4J messages from
// core end up coming through this tasks logger
StaticLoggerBinder.getSingleton().setTask(this);
AntTaskHolder.setTask(this);
}

public Settings getSettings() {
Expand Down Expand Up @@ -121,6 +121,7 @@ public final void execute() throws BuildException {
executeWithContextClassloader();
} finally {
Thread.currentThread().setContextClassLoader(current);
AntTaskHolder.remove();
}
}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@
import org.owasp.dependencycheck.utils.Downloader;
import org.owasp.dependencycheck.utils.InvalidSettingException;
import org.owasp.dependencycheck.utils.Settings;
import org.slf4j.impl.StaticLoggerBinder;
import org.owasp.dependencycheck.ant.logging.AntTaskHolder;

/**
* An Ant task definition to execute dependency-check update. This will download
Expand Down Expand Up @@ -222,7 +222,7 @@ public Update() {
super();
// Call this before Dependency Check Core starts logging anything - this way, all SLF4J messages from
// core end up coming through this tasks logger
StaticLoggerBinder.getSingleton().setTask(this);
AntTaskHolder.setTask(this);
}

/**
Expand Down
115 changes: 0 additions & 115 deletions ant/src/main/java/org/slf4j/impl/StaticLoggerBinder.java

This file was deleted.

4 changes: 0 additions & 4 deletions ant/src/main/java/org/slf4j/impl/package-info.java

This file was deleted.

Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
org.owasp.dependencycheck.ant.logging.AntSlf4jServiceProvider
Copy link

Copilot AI Feb 15, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This SLF4J service descriptor is under src/main/resources, but ant/pom.xml’s configuration only includes /*.properties from that directory. As a result, this file is likely not being packaged into the jar, and the SLF4JServiceProvider won’t be discoverable at runtime. Update ant/pom.xml resource includes to also include META-INF/services/ (or remove the restrictive includes) so this descriptor is shipped.

Copilot uses AI. Check for mistakes.
4 changes: 2 additions & 2 deletions pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -122,8 +122,8 @@ Copyright (c) 2012 - Jeremy Long
<apache.ant.version>1.10.15</apache.ant.version>

<!-- upgrading slf4j and logback can cause issues ;) https://github.com/dependency-check/DependencyCheck/issues/4846 -->
<slf4j.version>1.7.36</slf4j.version>
<logback.version>1.2.13</logback.version>
<slf4j.version>2.0.17</slf4j.version>
<logback.version>1.5.25</logback.version>

<maven.api.version>3.6.3</maven.api.version>
<reporting.checkstyle-plugin.version>3.6.0</reporting.checkstyle-plugin.version>
Expand Down
Loading