Package
elasticsearch-8.17
Component
log4j-1.2-api
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
ES 8.17.10 source does not depend on com.google.errorprone:error_prone_annotations, and log4j-api 2.25.x references @InlineMe from that package; bumping to 2.25.4 causes compileJava to fail. The bundled log4j 2.19.0 cannot be updated without invasive source-level changes (backporting an explicit errorprone dependency to ES 8.17). Tracking for follow-up.
Status