4 ms·
I don’t think it is a tautology , but I can imagine a cve scanner picking up older code with log4j where newer code may avoid that library altogether, just as a
by pylua 3y ago
I don’t think it is a tautology , but I can imagine a cve scanner picking up older code with log4j where newer code may avoid that library altogether, just as an example.
Since there is more older code than newer code would the llm be suspectible to that ?
- xmcqdpt2 3y agoEveryone still uses log4j after the fix. There aren't many full-featured alternatives... and the one that exist probably contain unfixed bugs.