@Aphrodite @cjust @calamari I was about to bring up the techpriests - following the Catechisms of Compliance but often not understanding why.

"our PCI scan shows this software is vulnerable" Yes because RHEL security backporting existed and you're only checking the version number and not if the vuln is actually there.