& Log4Shell. Thank you, Open-Source Software!
Summary
As so often these days, social media was quick to pour mockery and hate on this widely used logging framework and its developers who “implement software far from any quality controls”. The rest of the world (including us) can use these packages free of charge, integrate them into their customer projects, and ultimately earn money with them. However, this poses a great challenge for many software users, as it is often not easy to find out whether the affected library is included, especially in the case of third-party products that one did not develop himself. This self-developed software allowed us to identify all customer projects using Log4J at the push of a button on the morning of 10 December, shortly after the security breach became known. By the way, we use the DependencyTracker not only to track down third-party packages with security vulnerabilities, but also to ensure that the licenses of all used libraries allow them to be used in commercial projects.