Third-Party Dependencies in the Software Supply Chain
A class excerpt on why every third-party dependency you pull into a project becomes part of your software supply chain, and part of your attack surface. Staying current on dependency CVEs isn’t optional busywork, it’s part of the job.