Dependency response after the emergency patch
Emergency remediation revealed that many organisations could build software faster than they could establish which component version was running in each environment.
Reconcile declared and deployed code
Compare build manifests with final archives, shaded packages, container layers and vendor appliances. Record products that bundle Java components without exposing their versions and require suppliers to provide a testable remediation statement.
Separate mitigation from removal
Configuration changes and traffic filtering can reduce immediate exposure but do not remove a vulnerable library. Track temporary mitigations with owners and expiry dates until patched artefacts are deployed and the old images are no longer runnable.
Rehearse the next query
Choose another common library and time how long it takes to locate every affected service and owner. Improve build provenance, image retention and environment inventory until the answer comes from evidence rather than a broadcast request.
An incident is not closed while vulnerable images remain in registries, rollback slots or dormant scheduled workloads without an explicit exception.