Check project dependencies, base images, operating-system packages, infrastructure providers, plugins, and agent tools against current vulnerability and active-exploitation sources. Use before release, after dependency changes, during incident review, and on a schedule for long-lived services. Record source, timestamp, reachability, exploitability, mitigation, owner, and release impact.