Fixing the code is only half of incident response. Without an advisory, affected-version range, and downstream notification, users cannot know whether they remain exposed.