ISC2 CISSP Practice Question
What is the PRIMARY security concern related to using third-party code or components hosted in public repositories?
The risk of embedding components with deliberately obfuscated vulnerabilities
The potential for dependency confusion attacks targeting internal packages
The potential for repository infrastructures to be compromised to distribute malicious code
The lack of formal security assurance processes for contributed code