Thanks a lot for the information. I am going to remove the
sbml-3.4.0.jar.
I am not sure if you can answer the following questions:
1. Our security teams are highlighting certain files that show up because of Cytoscape. This includes the ones in the CytoscapeConfiguration directory that the user mentioned above, something like:
${HOME}/CytoscapeConfiguration/3/karaf_data/cache/bundle[XYZ]/version0.0/bundle.jar-embedded/log4j-*.jar
They are recreated every time a restarts Cytoscape. The JAR files contain the JndiLookup class. Any suggestion how we should deal with this? I am assuming 3.9.1 will include the newer fixed log4j JAR, which would be final solution.
2. Similarly, this file is being flagged in the Cytoscape installation directory (versions 3.7.1 and 3.8.2):
framework/system/org/ops4j/pax/logging/pax-logging-log4j2/1.10.1/pax-logging-log4j2-1.10.1.jar
This also contains the JndiLookup class. Can I remove this class from this JAR file and expect Cytoscape to function normally?
I really appreciate your help.
Nitish