home.social

#log4j — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #log4j, aggregated by home.social.

fetched live
  1. Are there any #log4j experts around here? I’m having problems upgrading log4j 1 to log4j 2 - I have an appender that’s used in tests to detect certain log output of the object under test (which is using an slf4j logger; the log4j 2 bridge is on the class path). Tests that use this to sense reset the logging subsystem before, and add this appender. They reset after. Each test passes when run in isolation; the full suite runs with tests either not capturing, or not matching visually good results.

  2. Endlich mal wieder Lust auf Podcast.

    Heute eine interessante Folge aus dem letzten Jahr über Menschen, die Open Source entwickeln. Mit Schwerpunkt auf log4j, aber eigentlich geht es vor allem um die Last auf Menschen, die als Hobby weit verbreitete Projekte pflegen und dabei weit seltener mit Dank als vielmehr mit Verantwortung und Ansprüchen konfrontiert sind.

    br.de/mediathek/podcast/wild-w

    #OpenSource #log4j #podcast #xzutils

  3. What did Log4Shell teach us about securing open source?

    Join the ORC WG on Monday to explore the lessons from Log4Shell and what a CRA-ready Log4j looks like.

    📆 March 16 at 12 pm EDT
    ➕ Add to your calendar: buff.ly/GZ8m6Gv

  4. Log4Shell revealed just how deeply open source runs through the global software supply chain—and how hard it can be to respond when a critical dependency fails.

    Join the ORC WG for the next to explore the lessons from Log4Shell and what it takes to build a CRA-ready Log4j.

    📆 March 16 at 12 pm EDT
    ➕ Add to your calendar: bit.ly/3PuQozy

  5. weil jeder mit nem claude abo denkt er sei jetzt plötzlich security researcher und die bug bounty programme diverser opensource projekte mit slop flutet, stellen jetzt cURL und log4j ihre ein!

    die welt ein bisschen unsicherer machen - dank KI! 😠
    #cURL #log4j #KI #BugBounty #CyberSecurity #foss #opensource

  6. 4 years already since the Log4J incident. That was not a fun time, but this meme made me laugh again this morning. 😆

    #SysAdmin #Log4J #Meme

  7. People. Why you gotta do me like this? Even knowing CICD pipes for versions of software that was retired years ago are still chugging along (oh yeah, I know about that one!!) this is an nsane number.

    infosecurity-magazine.com/news

    #log4j #cicd

  8. RE: ohai.social/@senficon/11541721

    #Log4j is popular.
    #OpenSource funding is necessary.
    Thanks to the @sovtechfund, which did so much for us after Log4shell!

  9. (repost from GitHub blog) The internet was on fire. 🔥
    One small library affecting billions of systems.
    Log4Shell was the biggest security vulnerability of all time.

    Now, Log4J maintainer, Christian Grobmeier tells us what it felt like inside the flames .

    github.blog/open-source/inside #github #security #log4j #oss #maintainers #opensource

  10. I never imagined GitHub would ask me to speak about Log4Shell.
    But it happened.

    GitHub asked me to share the story as I lived it, for the benefit of all maintainers and users of open source. How could I say no?

    I hope it helps build a more secure future.

    No more Log4Shell.

    github.blog/open-source/inside

    #opensource #log4j #Log4Shell #programming #security #hacking #Github

  11. #Log4j could have failed many times. But it survived. Not because of money, but because of people. An honest look behind the scenes — from the first line of code to the project’s greatest crisis.

    Read Christian Grobmeier’s new piece: javapro.io/2025/06/10/the-long

    #Log4Shell @theasf

  12. After #Log4Shell hit, I dreamed of writing a Java Logging book.
    Beginner-friendly and full of what I’ve learned as a trainer.

    Today, that dream became real.
    @ManningPublications just launched my book in their MEAP program, and I’m incredibly proud and grateful.

    After all these years at the ASF, it feels like a circle has closed.

    Get it 50% off:

    hubs.la/Q03Jv97D0

    #log4j #java #programming #opensource

  13. „Was, wenn wir im Urlaub gewesen wären?“ #Log4Shell traf 2021 Millionen Systeme – ein paar Freiwillige retteten das Netz. Christian Grobmeiers Rückblick auf 30 Jahre #Log4j zeigt, was #OpenSource leisten kann & dessen Grenzen, wenn Firmen nur konsumieren!

    javapro.io/de/die-lange-geschi

  14. Is it possible that #Log4j will be the most expensive global #InfoSec incident ever, *not* because of meaningful losses stemming from successful exploitation, but because it continues to be part of the continuous “#SBOM and patch all the things will fix this!!” drumbeat?

  15. Thinking about #InfoSec organizational behaviors derived from cognitive bias. In particular, availability bias from things that are memorable.

    #Log4j #Heartbleed #SolarWinds #ShellShock #Spectre #Meltdown #SQLSlammer

  16. Podcast-Empfehlung: Wild Wild Web - Geschichten aus dem Internet: #04 Das wichtigste Hobby der Welt [1][2]

    Es geht um Open Source Maintainer, und u.a. Finanzierung von OSS, die Sicherheitslücke in log4j 2021 und die Backdoor in xz 2024.

    Das Thema mal aus der nicht-technischen Außenperspektive des Podcasts zu sehen, war echt ne interessante Sache.

    #podcast #wildwildweb #foss #oss #opensource #log4j

    ___

    [1] Episode webpage: br.de/mediathek/podcast/wild-w
    [2] Media file: media.neuland.br.de/file/21080

  17. Think #Log4Shell was a one-off bug? Think again.. What really caused it? How close was #Log4j to dying — multiple times? And what’s next for one of #Java’s oldest libraries? Christian Grobmeier’s new piece will surprise you.

    Dive in: javapro.io/2025/06/10/the-long

    #JVM #Java @theasf

  18. #Log4j begann als EU-Forschungsprojekt in den 90ern. Heute ist es eins der meistgenutzten #Java-Logging-Frameworks & überlebte #Log4Shell.
    Wie ging das?

    Christian Grobmeier 👉 Die Geschichte eines Projekts zwischen #OpenSource, Sicherheit & Verantwortung: javapro.io/de/die-lange-geschi

  19. So I'm googling+udm14 if someone has made an lnav format for minecraft (client + server) logs: "lnav minecraft log".

    First link is the #lnav page, but without mentioning #minecraft.

    Second link is from minecraft wiki:

    "There are nine types of logs: oak, spruce, birch, jungle, acacia, dark oak, mangrove, cherry blossom, and pale oak; and two types of stems: crimson, and warped."

    Right... I need to be more specific.

    #unix

    (Joke aside, it should be #log4j, but lnav doesn't recognize it.)

  20. Would YOU patch a global CVE… unpaid… over your vacation? That’s what the #Log4j team did. But the full story goes way deeper — punk roots, #OpenSource fights, near-abandonment & one massive comeback.

    Read Christian Grobmeier’s story: javapro.io/2025/06/10/the-long

    #JVM @theasf

  21. How did a tiny Java logging lib bring the internet to its knees? How did unpaid devs patch it in the middle of global panic? And what’s next for #Log4j? Christian Grobmeier takes you inside one of #OpenSource’s wildest stories.

    Read it now → javapro.io/2025/06/10/the-long

    #JVM #Java