RT GitHub Security
As security teams globally work to assess Log4j exposure and patch, GitHub’s Dependabot can help by quickly identifying explicit vulnerable dependencies.
https://github.blog/2021-12-14-using-githubs-security-features-identify-log4j-exposure-codebase/
https://twitter.com/GitHubSecurity/status/1470884176953888769