apache / apache/logging-log4j2

Bump Apache Velocity Engine to version 2.x

Open
#1,461 0 comments 1 reaction 0 assignees View on GitHub
build dependencies
Dominant language
Java
Stars
3.6k
Forks
1.7k
Avg merge
21h 30m
Merged PRs (30d)
27

Description

## Description

We should consider moving away from the unmaintained Velocity 1.x: it starts collecting security advisories, like the one on our [Dependabot alerts page](https://github.com/apache/logging-log4j2/security/dependabot).

If we continue to use Maven Site Plugin, we need to bump its version to 4.x (which is in its alpha stage). However the current versions (2.x) of `asciidoctor-maven-plugin` are not compatible with version 4.x of Maven Site Plugin, so we are blocked until asciidoctor/asciidoctor-maven-plugin#578 is resolved.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.