Logback is a reliable, generic, fast and flexible logging library for Java.
It's intended as a successor to the popular log4j project.
The logback-core module lays the groundwork for the other two modules.
The logback-classic module can be assimilated to a significantly improved
version of log4j. Moreover, logback-classic natively implements the SLF4J API
so that you can readily switch back and forth between logback and other
logging systems such as log4j or java.util.logging (JUL).
The logback-access module integrates with Servlet containers, such as Tomcat
and Jetty, to provide HTTP-access log functionality.


2018-12-10 - Emmanuel Bourg <>
logback (1:1.2.3-5) unstable; urgency=medium
* Team upload.
* Fixed the compatibility with Jetty 9.4
2018-12-03 - Emmanuel Bourg <>
logback (1:1.2.3-4) unstable; urgency=medium
* Team upload.
* Depend on libtomcat9-java instead of libtomcat8-java
2018-11-11 - Emmanuel Bourg <>
logback (1:1.2.3-3) unstable; urgency=medium
* Team upload.
* Fixed the build failure with Java 11 (Closes: #911183)
* Removed Damien Raude-Morvan from the uploaders (Closes: #889387)
* Standards-Version updated to 4.2.1
* Switch to debhelper level 11
* Use Vcs-* URLs
2017-11-30 - tony mancill <>
logback (1:1.2.3-2) unstable; urgency=medium
* Team upload.
* Freshen debian/copyright for current upstream
* Bump Standards-Version to 4.1.2
* Add myself to Uploaders
* Use https for Homepage URL
* Upload to unstable after building r-deps.
2017-11-28 - tony mancill <>
logback (1:1.2.3-1) experimental; urgency=medium
* Team upload.
* New upstream version 1.2.3
* Disable and clean-up unused patches
* Add build-dep on libgmavenplus-java
* No longer rename javax.servlet-api artifact in debian/maven.rules
* Add ant-junit and maven-cal10n-plugin to maven.ignoreRules
* Update groupId of org.hsqldb in maven.ignoreRules
2017-11-26 - tony mancill <>
logback (1:1.1.9-5) unstable; urgency=medium
* Team upload.
* Add wagon-ssh to maven.ignoreRules (Closes: #882472)
* Address privacy disclosure (external URL) in documentation HTML
* Bump Standards-Version to 4.1.1
2017-06-29 - Apollon Oikonomopoulos <>
logback (1:1.1.9-4) unstable; urgency=medium
* Team upload.
* Build and ship logback-access:
+ Un-ignore the logback-access artifact.
+ Patch logback-access to comply with the servlet 3.1 API (upstream commit
+ B-D on tomcat 8 and jetty 9 and force Debian's versions in
* Bump Standards to 4.0.0; no changes needed.
2017-04-04 - Markus Koschany <>
logback (1:1.1.9-3) unstable; urgency=medium
* Team upload.
* The patch for CVE-2017-5929 was incomplete. Add CVE-2017-5929-part2.patch
and really fix the issue. (Closes: #857343)
* Remove all test cases from CVE-2017-5929.patch and only apply the minimal
changes to make it easier to review the package. Tests are disabled anyway.
2017-03-28 - Markus Koschany <>
logback (1:1.1.9-2) unstable; urgency=medium
* Team upload.
* Fix CVE-2017-5929:
It was discovered that logback, a flexible logging library for Java, would
deserialize data from untrusted sockets. This issue has been resolved by
adding a whitelist to use only trusted classes. (Closes: #857343)
Thanks to Fabrice Dagorn for the report.
2017-01-23 - Emmanuel Bourg <>
logback (1:1.1.9-1) unstable; urgency=medium
* Team upload.
* New upstream release

