By February 10, 2022 Health Care Dive Apache tells Senate committee the Log4j vulnerability could take years to resolve While a software bill of materials could improve supply chain security, users still download vulnerable versions of software.