2.8.0 Release
- Support CVE-2022-23302, CVE-2022-23305 and CVE-2022-23307, See #259
- --fix option will remove following classes:
- For CVE-2022-23302: JMSSink.class
- For CVE-2022-23305: JDBCAppender.class
- For CVE-2022-23307: All classes in org.apache.log4j.chainsaw package
- --fix option will remove following classes: