at release, there should be zero critical/high CVEs in the code or dependencies.
at release, there should be zero critical/high CVEs in the code or dependencies.