如何从maven-dependency-plugin 3.3.0中排除Log4j 1.2.12依赖?
解决maven-dependency-plugin 3.3.0引入Log4j 1.2.12的安全隐患
可以通过在插件配置中排除Log4j依赖的方式解决这个问题,具体有两种可行写法:
写法一:直接排除Log4j依赖
给插件添加<dependencies>块,明确标记Log4j为provided并排除其所有子依赖,配置如下:
<plugin> <groupId>org.apache.maven.plugins</groupId> <artifactId>maven-dependency-plugin</artifactId> <version>3.3.0</version> <dependencies> <dependency> <groupId>log4j</groupId> <artifactId>log4j</artifactId> <version>1.2.12</version> <scope>provided</scope> <exclusions> <exclusion> <groupId>*</groupId> <artifactId>*</artifactId> </exclusion> </exclusions> </dependency> </dependencies> <executions> <execution> <id>copy-dependencies</id> <phase>package</phase> <goals> <goal>copy-dependencies</goal> </goals> <configuration>...</configuration> </execution> </executions> </plugin>
写法二:精准排除间接依赖
Log4j 1.2.12是通过maven-reporting-api间接引入的,直接在该依赖下排除Log4j更精准:
<plugin> <groupId>org.apache.maven.plugins</groupId> <artifactId>maven-dependency-plugin</artifactId> <version>3.3.0</version> <dependencies> <dependency> <groupId>org.apache.maven.reporting</groupId> <artifactId>maven-reporting-api</artifactId> <version>3.1.1</version> <exclusions> <exclusion> <groupId>log4j</groupId> <artifactId>log4j</artifactId> </exclusion> </exclusions> </dependency> </dependencies> <executions> <execution> <id>copy-dependencies</id> <phase>package</phase> <goals> <goal>copy-dependencies</goal> </goals> <configuration>...</configuration> </execution> </executions> </plugin>
修改后可以执行mvn clean package测试,copy-dependencies目标不需要Log4j也能正常完成依赖复制工作。
内容的提问来源于stack exchange,提问作者Matt Houser
相关产品推荐
相关产品推荐

