You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何从maven-dependency-plugin 3.3.0中排除Log4j 1.2.12依赖?

解决maven-dependency-plugin 3.3.0引入Log4j 1.2.12的安全隐患

可以通过在插件配置中排除Log4j依赖的方式解决这个问题,具体有两种可行写法:

写法一:直接排除Log4j依赖

给插件添加<dependencies>块,明确标记Log4j为provided并排除其所有子依赖,配置如下:

<plugin>
    <groupId>org.apache.maven.plugins</groupId>
    <artifactId>maven-dependency-plugin</artifactId>
    <version>3.3.0</version>
    <dependencies>
        <dependency>
            <groupId>log4j</groupId>
            <artifactId>log4j</artifactId>
            <version>1.2.12</version>
            <scope>provided</scope>
            <exclusions>
                <exclusion>
                    <groupId>*</groupId>
                    <artifactId>*</artifactId>
                </exclusion>
            </exclusions>
        </dependency>
    </dependencies>
    <executions>
        <execution>
            <id>copy-dependencies</id>
            <phase>package</phase>
            <goals>
                <goal>copy-dependencies</goal>
            </goals>
            <configuration>...</configuration>
        </execution>
    </executions>
</plugin>

写法二:精准排除间接依赖

Log4j 1.2.12是通过maven-reporting-api间接引入的,直接在该依赖下排除Log4j更精准:

<plugin>
    <groupId>org.apache.maven.plugins</groupId>
    <artifactId>maven-dependency-plugin</artifactId>
    <version>3.3.0</version>
    <dependencies>
        <dependency>
            <groupId>org.apache.maven.reporting</groupId>
            <artifactId>maven-reporting-api</artifactId>
            <version>3.1.1</version>
            <exclusions>
                <exclusion>
                    <groupId>log4j</groupId>
                    <artifactId>log4j</artifactId>
                </exclusion>
            </exclusions>
        </dependency>
    </dependencies>
    <executions>
        <execution>
            <id>copy-dependencies</id>
            <phase>package</phase>
            <goals>
                <goal>copy-dependencies</goal>
            </goals>
            <configuration>...</configuration>
        </execution>
    </executions>
</plugin>

修改后可以执行mvn clean package测试,copy-dependencies目标不需要Log4j也能正常完成依赖复制工作。

内容的提问来源于stack exchange,提问作者Matt Houser

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 11:35:29