We do not currently use CVE numbers and I'm not sure whether this is something we will implement, but all changes are logged on
this page. We don't explain every fix in great detail, but the affected component (deployment, warranty scanning etc.) is usually mentioned, so you should certainly update if you're using the components mentioned.