[Vulnix](https://github.com/nix-community/vulnix) could check for CVEs before building the iso.
Vulnix could check for CVEs before building the iso.