> Then you probably have over a dozen CVEs in your code.
We continuously monitor our dependencies for CVEs and update them if necessary. Most of the time the CVEs that are reported are not relevant / worth updating for.