Critical container base image patches exceed 30-day SLA
Nine production container images are running base layers with unpatched critical CVEs first detected between 41 and 78 days ago, exceeding the one-month patch window required by PCI DSS 6.3.3.
Remediation Rebuild affected images against the hardened base tag 2026.08 and enable the automated base-image bump job.