Beschreibung der Beschaffung
Logback is one of the most widely used logging frameworks in the Java community.
Logging describes the storing processes or data changes in special files. It helps administrators and developers in all phases from the development up to the operation of code in identifying and tracing errors.
In a security context, logging is particularly important for detecting system failures, cyberattacks or other events that can endanger a company, its data or its customers, at an early stage.
Logback is an alternative to log4j2, a logging framework in which a critical vulnerability was discovered at the end of 2021.
The vulnerability became known as "Log4Shell" and had far-reaching consequences. Several companies and organizations worldwide were affected by the vulnerability and had to investigate and update their systems. The developer of Logback attaches great importance to extensive testing options and limited functional options - both features increase security and reliability of Logback as a logging reliability of logback as a logging framework. In addition, logback was designed to be more performant than its predecessors log4j1 and log42.
In detail, the following milestones are planned:
1) Testing and adapting Logback to the latest JDK versions.
2) Testing and adapting Logback for GraalVM.
3) Processing of pending bug reports
4) Continuous monitoring of supply chain vulnerabilities.
5) SLF4J API improvements
6) Continued maintenance of reload4j
7) XML to Java logback configuration translator