Starting in RKE2 v1.37, every cluster runs a small, optional component called security-responder by default. It tells you which CVEs affect the RKE2 version you’re running, and what version to move to next. It does this automatically, in-cluster, without you having to track release notes or CVE feeds yourself.