4 ms·
They didn’t know it was vulnerable, they just didn’t like it for other reasons. Should maintainers of all core apache libs just remove or disable features they
by diroussel 5y ago
They didn’t know it was vulnerable, they just didn’t like it for other reasons.
Should maintainers of all core apache libs just remove or disable features they don’t like, when not known to be insecure?
That said, log4j2 isn’t that old. Not sure why this was added in the first place. At the very least it’s a performance issue.
- wpietri 5y ago> Should maintainers of all core apache libs just remove or disable features they don’t like, when not known to be insecure? I'd bet more will start doing so. If nobody is excited to keep the feature up and any unloved code contains risks, getting rid of it seems fine to me. If companies want that code maintained, they can pay up or get one of their people to do it.
- zamalek 5y ago> Should maintainers of all core apache libs just remove or disable features they don’t like, Why not? I can just go into a parity package.
- matkoniecz 5y ago> Should maintainers of all core apache libs just remove or disable features they don’t like, when not known to be insecure? If noone funds their development and they maintain it for free? Then yes, why not.
- manquer 5y agoIf you are not being paid for it why build features you don't like? That is what you do in your day job! Your hobby project should atleast should make you happy ?