-
Task
-
Resolution: Unresolved
-
Undefined
-
None
-
None
-
None
-
None
-
Quality / Stability / Reliability
-
False
-
-
False
-
Not Selected
-
-
Currently, we don't have any steps in the release process to see which container/RPM CVEs are being addressed with the release and so we only mention CVEs from Vulnerability JIRA tickets. This is a gap.
The process should be extended to do that. Ideally, we should get some automatic way (or at least a follow-up ticket for it).
See discussion in https://redhat-internal.slack.com/archives/C05TS9N0S7L/p1765380787244339?thread_ts=1765356461.361239&cid=C05TS9N0S7L