A software engineer discovered 580 CVEs across 16 deployments at 4am after building a custom infrastructure stack with homegrown orchestration, container registry, identity provider, and CI/CD pipeline. Using Software Bill of Materials generation and the Provenance vulnerability scanning platform, a critical flaw in a transitive dependency was automatically detected and flagged, triggering an alert that woke the engineer to address the issue.