Forum Discussion
Anonymous
4 years agoA propertysource would probably work better. Until simpler testing tools come out, you could ssh into your server and use something like syft to create a BoM and see if that BoM contains the offending version of log4j.