👤 cisagov | ⭐ +708 stars log4j-scanner is a project derived from other members of the open-source community by CISA to help organizations identify potentially vulnerable web services affected by the log4j vulnerabilities.
👤 Ivan | 👍 +22 reactions When you are maintaining a codebase it becomes hard to keep track and update the dependencies installed in your app. While it's important to keep things up to date, it's also a huge pain. Checking for updates, make sure nothing is breaking, etc. That's where Dependabot comes to help us, it automatically creates pull requests that we can review and test and, if it's all good, merge an update our dependencies.