A team is under deadline pressure to ship a container update. The security scan shows a high-severity CVE. What is the ethically correct action?
-
A
Ship the update and file a ticket to fix the CVE next sprint
-
B
Block the release until the CVE is patched or a formal risk acceptance is documented by stakeholders
-
C
Suppress the scan result to avoid delays
-
D
Deploy to production and monitor for exploitation