Even if a code change is approved we need to analyse the vulnerability, design a solution, develop the fix the, test the fix in QA, security review the code, security test the code, upload the code to pre-production, test again and if everything is still working we deploy it into production.