問題文
A build pulls a package from a public index on every run, and the maintainer of that package published a new version overnight. Which option lists the controls that keep an unreviewed change out of the next release?
選択肢
- The team should pin every dependency to an exact branch recorded in a tar file, and it should mirror approved packages into an internal gateway so that a build never reaches the public index without a backup of what it fetched.
- The team should pin every dependency to an exact version recorded in a lock file, and it should mirror approved packages into an internal registry so that a build never reaches the public index without a record of what it fetched.
- The team should pin every dependency to an exact branch recorded in a tar file, and it should mirror approved packages into an internal registry so that a build never reaches the public index without a record of what it fetched.
- The team should pin every dependency to an exact version recorded in a lock file, and it should mirror approved packages into an internal gateway so that a build never reaches the public index without a backup of what it fetched.