The post-mortem meeting is now considered an on-demand event. The past few security release cycles proved that there is rarely a need to discuss things in this form, so there is little point in carrying out the relevant steps for every single vulnerability - which does not prevent us from doing so if the actual need arises.