A post was split to a new topic: Can SonarQube detect code that used the Log4J2 in a way that is vulnerable?