Published onSeptember 29, 2026Whose CVE is it anyway?openshiftkubernetesrhacssecuritybaseapplicationvulnerabilityExploring separation of duties across the application lifecycle. Whose responsibility is it to manage CVEs in base images, vs the application? And how do you provide tools to manage this security boundary?