dear #appsec people, I'm curious how you deal with 3rd party dependencies. do you use a scanner that reports cves? manual audits? have external audits done?
and any difference in dealing with opensource and closed source libs?
and if you audit, how do you determine scope of which part to audit? you can determine the library code used, but that might change 1 commit later.