Ask not if our product uses Apache Struts, but...
When it was revealed that the massive Equifax breach in 2017 was attributed to their failure to patch a component in their system known as ‘Apache Struts’, everyone was reaching out to their development teams and asking: “Do we use Apache Struts? Is it patched?”
And I found it interesting. In my opinion, the wrong question was being asked.
What they should be asking us (and what we should be doing) is: