NHSDigital / software-engineering-quality-framework

🏎️ Shared best-practice guidance & tools to support software engineering teams
147 stars 35 forks source link

Supply Chain Security & 3rd-Party Code Packages #242

Open jameszwiers opened 2 years ago

jameszwiers commented 2 years ago

We should be defining best practice around how we review and validate the origin of 3rd-party code that we make use of.

We need to consider areas ranging from:

Likely other matters that need to be considered as well, and we should definitely ask Cyber for input as well.