Six months of the same cycle. Critical CVE drops, we rebuild, scanner clears, three weeks later another one surfaces from a transitive dependency we didn't even know was in the base image.…
Adding features to a broken foundation produces a faster-failing app. Here is the decision framework for knowing when to stop building on what you have.