What's wrong with CVEs? Daniel Stenberg of cURL wants you to know
podcast.sustainoss.org
podcast.sustainoss.org
Most other maintainers I've talked to feel very similarly. I just had an interview with a research group a few days ago who said this wasn't an unpopular opinion, either.
This approach to security is extremely harmful overall, and I'm glad Daniel is speaking frankly about it. He's spot on.
That sounds more like a problem with the compliance team in question having policies that are flawed in one or more ways.
One entity blindly/inflexibly/irrationally/wrongly reacting to some other entity's proclamation isn't the fault of the entity making the proclamation.
Bank "Your container is showing this CVE"...
Us: "Any container that uses library X will show this CVE"
Bank "You have to get rid of the CVE"
Us: "You cannot get rid of that CVE because your software checks for the existence of the library, not the existence of a potentially weak configuration that could cause a problem. This is like saying we have to get rid of the car because it contains gas, rather than ensuring we have safe gasoline storage practices"