update to log4j 1.2.17 in dependency tree
diff --git a/pom.xml b/pom.xml
index 9e529c4..8ea9b36 100644
--- a/pom.xml
+++ b/pom.xml
@@ -153,6 +153,12 @@
         <artifactId>aether-util</artifactId>
         <version>${aetherVersion}</version>
       </dependency>
+      <!-- log4j 1.2.12 is pulled in by commons-logging via Velocity 2 via Doxia 1  -->
+      <dependency>
+        <groupId>log4j</groupId>
+        <artifactId>log4j</artifactId>
+        <version>1.2.17</version>
+      </dependency>
     </dependencies>
   </dependencyManagement>