Who is responsible for patching a security vulnerability contained in the code of a customer application that runs on an Amazon EC2 instance?