Bump org.apache.logging.log4j:log4j-api from 2.22.1 to 2.25.5 #2589

Open
dependabot[bot] opened 7:34pm on August 13, 2026 wants to merge 1 commit into apache/systemds main from
dependabot/maven/org.apache.logging.log4j-log4j-api-2.25.5

Pull Request Overview

  • Opened on August 13, 2026
  • Status Open
  • Commit count 1 with first commit August 13, 2026

Total Delta

0 Total Diff Delta

Open Days

Open 27 weekdays

Test Delta

0 Diff Delta in Test Files
Breakdown by Phase

How long has this pull request spent in each phase of its lifecycle?

Data pending calculation for pull request

Author avatar

Bump org.apache.logging.log4j:log4j-api from 2.22.1 to 2.25.5

Bumps org.apache.logging.log4j:log4j-api from 2.22.1 to 2.25.5.

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/apache/systemds/network/alerts).

No comments have been left on this PR.