Ensure all Jenkins jobs are working for the CPS repositories that are part of Montreal release,
Update the vulnerable direct dependencies in their code base following the recommendations of SECCOM documented in Montreal CPS.
Identify resource or technical constraints to SECCOM by (M2).
Submit a LF Ticket for access to the Security Vulnerabilities space (if needed).
Execute packages upgrades accordingly.
Update statuses in the restricted Wiki (link above).
For the agreed resource or technical constraints provide waiver status with declaration on when it is planned to be solved.