Demo Case: Java with DolphinScheduler - Log4Shell
Scan and remediate a real Java project to migrate away from a vulnerable logging dependency.
Prerequisites
Step 0: Prepare the demo repo
git clone https://github.com/iac-playground/dolphinscheduler.git<slf4j.log4j12.version>1.7.5</slf4j.log4j12.version><dependency>
<groupId>org.slf4j</groupId>
<artifactId>slf4j-log4j12</artifactId>
<version>${slf4j.log4j12.version}</version>
</dependency>Step 1: Run the first scan

Step 2: Review findings
Step 3: Inspect finding details

Step 4: Preview fixes

Step 5: Review diffs in detail

Step 6: Apply fixes from the Webview Reviewer
Step 7: Validate changes locally (recommended)
Step 8: Re-scan to confirm findings are resolved
Last updated