Replace ActiveMQ docker image with security vulnerabilities #155
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Short description of the changes:
When deploying WebMon to the test environment Randy got a security exception in the ActiveMQ broker deployment, due to the dependency log4j1.2.17. "the security scan is saying we need log4j 2.16 or later"
This change replaces the ActiveMQ broker docker image from the archived repo https://github.com/rmohr/docker-activemq with an official ActiveMQ docker image from Apache: https://hub.docker.com/r/apache/activemq-classic.
The new broker uses a log4j version > 2.16:
Check list for the pull request
Check list for the reviewer
References
Defect 3940: Replace ActiveMQ docker image