When Dependabot Is Worse Than Nothing: Log4J As A Sub-Dependency