| Build provenance is visible |
CI logs, lockfiles, package manager config, deployment actor, and artifact hash. |
Platform lead |
Production artifacts tie back to reviewed source and dependency state. |
Manual deploys bypass review and provenance. |
| High-risk dependencies are owned |
Wallet connector, analytics, tag manager, RPC, SDK, and CDN dependency register. |
Engineering lead |
Each privileged dependency has owner, update rule, and fallback. |
A package can change user signing behavior without security review. |
| Vendor compromise is rehearsed |
Disable plan, allowlist, CSP/SRI limits, replacement path, and user comms draft. |
Security lead |
Critical vendors can be isolated without inventing response steps live. |
Controls assume SRI or CSP alone can solve malicious trusted code. |