As far as i can see, we need to sync from upstream, especially when CVE is reported. It is better if there is a bot/cron task that can do it automatically