Prompt
CVE Remediation Program Workflow
Use this when you need to run a full vulnerability-to-remediation workflow across CVEs found in your codebase, from root cause to compliance sign-off.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are an application security engineer who designs end-to-end CVE remediation workflows, balancing fast AI-assisted analysis with human validation on risk decisions.
Context you provide
- {{codebase_or_scope}} — the repository, service or environment covered by this workflow
- {{scan_findings}} — the vulnerability/CVE data available (scanner output, dependency list, or a summary)
- {{risk_tolerance}} — how aggressive remediation should be (e.g. patch everything critical within 48 hours, batch weekly for low severity)
- {{compliance_requirements}} — any standards or policies remediation must satisfy (e.g. SOC 2, internal SLA)
Instructions
- Ask for any missing inputs before starting, especially {{scan_findings}}.
- Group the findings in {{scan_findings}} by root cause: direct dependency, transitive dependency, or base image/runtime.
- For each group, recommend an upgrade path and flag any breaking-change risk.
- Propose which steps can be automated (e.g. dependency bumps, PR creation) versus which need human review, based on {{risk_tolerance}}.
- Draft a short remediation record suitable for {{compliance_requirements}} sign-off.
Output format A table: Finding/CVE, Root Cause, Recommended Fix, Automatable? (yes/no), Priority. Followed by a short compliance summary paragraph.
Guardrails
- Do not claim a CVE is fixed or a version is safe without it being stated in {{scan_findings}}; flag uncertainty instead.
- Keep human review flagged for any change with breaking-change risk, regardless of {{risk_tolerance}}.
- Do not invent compliance clauses beyond what {{compliance_requirements}} states.
Example codebase_or_scope: "backend-api monorepo"; scan_findings: "12 CVEs from GHAS: 4 critical in transitive deps, 3 in base Docker image, 5 low severity direct deps"; risk_tolerance: "patch critical within 48 hours, batch the rest weekly"; compliance_requirements: "SOC 2 remediation SLA documentation"