Remediation & Patching

Once something risky is in your inventory, decide what to fix first, test the fix safely, and ship a hardened configuration.

Policy keeps new risk off the install path; remediation deals with what is already in your inventory. This section ranks what to patch first by real-world exploit signal, lets you rehearse a patch before rolling it, packages a hardened configuration, and answers the “are we affected by CVE-X?” question every team eventually gets asked. Chainsaw ranks and rehearses; it does not open the upgrade PR — that stays with your existing patch tooling.

Prioritize by exploitability, not raw CVE count. The leaderboard ranks by KEV and EPSS so you fix the handful of issues attackers are actually using before chasing low-signal noise.

Where to next

The inventory and SBOMs these guides query come from Provenance & SBOM; roll a hardened config out org-wide from Monitoring & Compliance.