@domi @wolf480pl @lanodan kinda same, for most of my boxes I just keep non-breaking repo upgrades running on autopilot, and for containers/etc subscribed to releases on GitHub (Watch -> Custom -> Releases) et al so that I get notification emails whenever they draft a new release, then update to the latest greatest ASAP. Keeping up with the entire firehose on oss-security etc seems like a full-time job, corporate scanners is just extremely expensive security cosplay.