On Wed, 29 Dec 2021 at 14:49, Xeno Amess <xenoam...@gmail.com> wrote: > > log4j2 recently, in vfs...
Log4j2 would have been known about without Dependabot. > sebb <seb...@gmail.com> 于2021年12月29日周三 22:48写道: > > > Genuine question: has Dependabot alerted us to any security issues? > > > > If so which ones, and was it the only alert mechanism for that issue? > > > > Sebb > > > > --------------------------------------------------------------------- > > To unsubscribe, e-mail: dev-unsubscr...@commons.apache.org > > For additional commands, e-mail: dev-h...@commons.apache.org > > > > --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@commons.apache.org For additional commands, e-mail: dev-h...@commons.apache.org