Supply-Chain

The New Dependency Dilemma

A dependency received a critical security patch. An immediate update seems mandatory, but doing so opens the doors for supply-chain attacks. Where's the escape hatch?