To quickly and reliably determine if we're impacted by a CVE, we need to be able to check all repos, at all release tags and at the tip of all release branches.
I think the best way to determine this is with go mod graph. That shows all direct and indirect dependencies, and why they are needed.