Introduction Problem Statement The Oracle Cloud Native Core software currently provides six planned releases per year (program increments), and each release will contain a mix of features and fixes. In each release we typically move 3rd party software to the latest release in order to stay abreast of the latest security patches for our embedded 3rd party software. This can lead to an two to three month lag for the release of critical security vulnerabilities, which isn't acceptable for critical fixes. And as we typically only address vulnerabilities on the tip of the release under-development, a customer who has not yet moved to the latest release would need to upgrade to pick up a critical security fix. Currently we only scan products that are under development; once released (posted to OSDC or MOS) we do not go back and rescan. Because 3rd party vulnerabilities may be found after we have released our software, a ...